Vulnerability in Ember Sword NFT auction contract leads to $195,000 in losses

Security experts from CertiK discovered a critical vulnerability in the Ember Sword NFT auction contract, leading to financial losses for 159 users totaling $195,000.

The vulnerability affected users who approved the Ember Sword NFT contract, allowing attackers to obtain approximately 60 WETH. Certik recommended revoking approval of the relevant contract on the Polygon blockchain as soon as possible.

The vulnerability in the Ember Sword NFT contract allowed fraudsters to manipulate bids and withdraw funds from users of the service. Certik believes the vulnerability was caused by an error in the Ember Sword NFT auction contract code.

Users are requested to immediately revoke the authorization for the contract address starting with 0x389 on the BSC chain and the contract address starting with 0x6f7 on the Polygon chain.

Fraudulent bids could override users’ legitimate bids, resulting in attackers winning auctions at lower prices. They could then sell NFTs at higher prices, profiting from the difference.

Rate this article
( No ratings yet )
Chainspot News