The smart contract vulnerability arises after the integration of ERC-2771 and multicall standards. OpenZepplin identified 13 sets of vulnerable smart contracts.
168 Total views
4 Total shares
Soon after Thirdweb revealed a security vulnerability that could impact a variety of common smart contracts used across the Web3 ecosystem, OpenZeppelin identified two specific standards as the root cause of the threat.
On Dec. 4, Thirdweb reported a vulnerability in a commonly used open-source library, which could impact pre-built contracts, including DropERC20, ERC-721, ERC-1155 (all versions) and AirdropERC20.
IMPORTANT
On November 20th, 2023 6pm PST, we became aware of a security vulnerability in a commonly used open-source library in the web3 industry.
This impacts a variety of smart contracts across the web3 ecosystem, including some of thirdweb’s pre-built smart contracts.…
— thirdweb (@thirdweb) December 5, 2023
In response, smart contracts development platform OpenZepplin and nonfungible token marketplaces Coinbase NFT and OpenSea proactively informed users about the threat. Upon further investigation, OpenZepplin found that the vulnerability stems from “a problematic integration of two specific standards: ERC-2771 and Multicall.”
The smart contract vulnerability in question arises after the integration of ERC-2771 and multicall standards. OpenZepplin identified 13 sets of vulnerable smart contracts, as shown below. However, crypto service providers are advised to address the issue before bad actors find a way to exploit the vulnerability.
OpenZepplin’s investigation found that the ERC-2771 standard allows overriding certain call functions. This could be exploited to extract the sender’s address information and spoof calls on their behalf.
OpenZepplin advised the Web3 community using the aforementioned integrations to use a 4-step method for ensuring safety: disable every trusted forwarder, pause contract and revoke approvals, prepare an upgrade and evaluate snapshot options.
IMPORTANT
On November 20th, 2023 6pm PST, we became aware of a security vulnerability in a commonly used open-source library in the web3 industry.
This impacts a variety of smart contracts across the web3 ecosystem, including some of thirdweb’s pre-built smart contracts.…
— thirdweb (@thirdweb) December 5, 2023
In addition, Thirdweb launched a mitigation tool that allows users to connect their wallets and identify if a contract is vulnerable.
Today the @OpenZeppelin team disclosed details about the @thirdweb vulnerabilities to our team. We’ve identified a few functions in the Relay contracts that could be griefed. As such, we are deactivating Relay until the necessary adjustments can be made.
To be absolutely clear,…
— Velodrome (@VelodromeFi) December 8, 2023
The decentralized finance platform Velodrome also deactivated its relay services until a new version was installed.
Related: Coinbase’s Base network gets OpenZeppelin security integration
In a recent Cointelegraph Magazine article, experts revealed how artificial intelligence (AI) can help audit smart contracts and aid cybersecurity efforts.
gm ☕️
As someone with zero Solidity proficiency, I had an already efficient smart contract tailored to my own needs by AI.
I dumped @Azuki’s smart contract into GPT-4 and had it ask me relevant questions.
Disclaimer: Professional human audits and devs are still important to… pic.twitter.com/K4UGfFC5dp
— SV (@0xSMV) March 16, 2023
James Edwards, the lead maintainer for cybersecurity investigator Librehash, said that while AI chatbots can develop smart contracts, deploying them in a live environment is risky.
On the other hand, Edwards highlighted the technology’s potential to vet smart contracts. Recent tests showed AI’s ability to “audit contracts with an unprecedented amount of accuracy that far surpasses what one could expect and would receive from GPT-4.”
While he concedes it’s not as good as a human auditor yet, it can already do a strong first pass to speed up the auditor’s work and make it more comprehensive.
Magazine: Lawmakers’ fear and doubt drives proposed crypto regulations in US
Venmo, a versatile financial application, provides a range of features, including peer-to-peer (P2P) money transfers and cryptocurrency transactions. Serving as a comprehensive financial tool, Venmo enables users to seamlessly handle transactions, including the option to participate in digital currencies like Bitcoin (BTC). The app is designed to simplify financial operations and assist users in navigating
Marijuana culture media group High Times Holding Corp. has decided not to accept Bitcoin (BTC) in its initial public offering (IPO), according to an August 13 filing with the U.S. Securities and Exchange Commission (SEC). The decision runs counter to the company’s Aug. 3 announcement, where it stated it will accept cryptocurrencies in order to…
According to Bloomberg, financial giant Western Union has made an offer to purchase cross-border payments company MoneyGram. 1518 Total views 47 Total shares Western Union might be purchasing cross-border payments company MoneyGram.According to a June 1 article on Bloomberg, the payments giant recently made a takeover offer for MoneyGram. If successful, this would combine the…
The United States regulatory body, the Financial Industry Regulatory Authority (FINRA), has charged one of Merrill Lynch’s staff $5,000 for mining cryptocurrency. Documents dated June 10 confirm the fine.According to the “letter of acceptance, waiver and consent” signed by the employee, Kyung Soo Kim, FINRA took action when it appeared the activities did not comply…
Amid the ongoing growth of the cryptocurrency lending industry, major crypto wallet service Blockchain.com launches a new lending product for all users, not just institutions.After first launching an institutional crypto lending desk in August 2019, Blockchain.com is now rolling out its crypto lending service to all users across more than 180 countries, the United Kingdom-based…
Head of Facebook's Calibra claimed that the recent withdrawal of the seven firms from the Libra Association has no impact on the project.Dropouts will still be able to work with LibraIn an interview with Yahoo Finance on Oct. 15, Calibra’s David Marcus argued that Facebook’s cryptocurrency project is “absolutely not” in jeopardy after PayPal, Visa,…
The commercial real estate sector is squarely in the sights of the blockchain industry. Advocates justifiably believe that the technology offers the ability to streamline everything from capital formation to transaction settlement at hitherto unseen levels of speed and efficiency. Additionally, through a process known as tokenization, blockchain platforms can create digital representations of shares…
A Dublin-headquartered startup has teamed up with the Irish Red Cross to use blockchain technology in a new app that improves transparency for charitable donations. The partnership was reported by local daily broadsheet The Irish Times on Dec. 19.The startup, dubbed AID:Tech, is partnering with the Red Cross for use of its consumer-oriented mobile app…