NFT Evening NFT Evening
    Facebook Twitter Instagram Reddit
    NFT Evening NFT Evening
    • News
      • Collectibles
      • Crypto Art
      • Blockchain games
      • Metaverse
      • Music
      • Interviews
    • Guides
      • Top NFT Projects
      • Top Blockchain Games
      • NFT Marketplaces and Tools
    • Learn here!
      • What is an NFT?
      • How to keep your NFTs safe
      • NFT Glossary
    • NFT Calendar
      • NFT Drops
      • NFT Conferences
    • Newsletter
    NFT Evening NFT Evening
    News

    Home » News » Check Point Research Finds Major Security Flaw On Rarible.com

    Check Point Research Finds Major Security Flaw On Rarible.com

    By Bryan TeohApril 15, 2022Updated:February 2, 20233 Mins Read
    Contents hide
    Malicious NFTs Hiding in Plain Sight
    Official Response by Rarible.com
    Check Point Research Safety Tips

    Earlier this month, Check Point Research alerted NFT marketplace Rarible.com regarding a major security flaw on the platform. The research team then worked closely with Rarible.com to install an immediate fix. This could have been a major heist if it was exploited, as the threat actor can steal a user’s NFTs and crypto tokens in a single transaction.

    Check Point Research finds Rarible security flaw
    Rarible.com avoids what could have been a major NFT heist. Credit: Rarible

    Malicious NFTs Hiding in Plain Sight

    Earlier this month, Taiwanese singer-songwriter and producer, Jay Chou had his Bored Ape and other NFTs swept away in an NFT heist. This motivated Check Point Research (CPR) to unearth similar threats hiding in plain sight. Fortunately, the team discovered the malicious NFTs on Rarible.com before it could be exploited. Such threats are worse than phishing attacks as users usually lower their guard on trusted marketplaces such as Rarible.com.

    According to CPR, the NFT has an EIP-721 token standard, which provides basic functionality to track and transfer NFTs. However, this standard also has a function called ‘setApprovalForAll’, where 3rd parties like Rarible.com and OpenSea can control digital assets on behalf of the users. As users typically do not read the details when they sign a transaction, they could have easily signed away all their assets to the hacker.

    Check Point Research demo hack
    CPR demonstrates how easy it is to execute the attack. Credit: Rarible

    Check Point Research created a simple SVG file to demonstrate how easy it is to sneak an attack into the platform. By clicking on the art and opening it in another tab, or by pressing on the IPFS link from the drop-down, the JavaScript code will be executed. After the hacker gets access to the account, he can then easily use the ‘transferFrom’ action to wipe the account clean.

    Official Response by Rarible.com

    After the event, the Rarible team released an official statement. It mentions that the identified vulnerability does not directly affect Rarible.com users, their wallets and their data. Instead, the vulnerability only affects users if they deliberately leave Rarible.com for a third-party resource with malicious content, and consciously sign suggested transactions with their wallets. Simply clicking the link is not enough, the exploit requires user interaction and confirmation for transactions.

    Since then, the team has been working closely with multiple cyber security teams including ChainSecurity. This is to proactively ensure a safe experience for their community.

    Check Point Research Safety Tips

    CPR is a research team that provides leading cyber threat intelligence to their clients and the crypto community in general. In essence, they collect and analyze global cyber attack data stored on ThreatCloud. CPR will continue to discover new cyber threats and develop the threat intelligence community to protect the entire industry.

    After this recent discovery, the company strongly recommends the following precautions. Firstly, users should always be careful and aware whenever they receive requests to sign any links. This applies to any marketplace and crypto exchanges. Before signing anything, users need to review the request and determine if it can potentially be malicious.

    It can be tempting to quickly sign a request when you’re in the middle of a gas war. Nevertheless, users should reject a request if there is the slightest bit of suspicion, and only accept after adequate examination. Lastly, the Ethereum Token Approval facility allows users to review and revoke any past token approvals to secure the accounts.

    Join Our New "To The Moon" daily Newsletter

    Get our free, 5 minutes daily newsletter. Join 25,000+ NFT enthusiasts & stay on top 👊🌚

    Thank you!

    You have successfully joined our subscriber list.

    .

     


    All investment/financial opinions expressed by NFTevening.com are not recommendations.

    This article is educational material.

    As always, make your own research prior to making any kind of investment.

    Previous ArticleTony Hawk Skateboard NFT Drop x A Chance To Win His Real Skateboard
    Next Article Green Bud Killers Club is Bringing the Love of Bong to the Blockchain
    Bryan Teoh

    Bryan is a content writer based in Malaysia. Aside from food and sports, his interests include blockchain, cryptocurrencies and NFTs.

    More great NFT Evening content:

    Spatial Metaverse Company Launches GDC Announcement Today

    March 24, 2023

    All the PFPs Invited on the Otherside Second Trip

    March 24, 2023

    Paris Blockchain Week: 4 NFT Trends to watch in 2023

    March 24, 2023

    Nike & RTFKT Team Up To Bring Physical Air Force 1 NFT Sneakers To Collectors

    March 24, 2023

    NFT Trading Soars in Virtual Worlds: $311M in Q1 2023, Says DappRadar

    March 24, 2023

    ZED RUN x Budweiser: Web3 Collaboration You Can Wear

    March 24, 2023

    MVFW 2023: A Peek at the Four Fashion-Filled Days Ahead

    March 24, 2023

    Yuga Labs Announces The Otherside 2nd Trip Captains

    March 23, 2023
    Latest NFT News

    Spatial Metaverse Company Launches GDC Announcement Today

    March 24, 2023

    All the PFPs Invited on the Otherside Second Trip

    March 24, 2023

    Paris Blockchain Week: 4 NFT Trends to watch in 2023

    March 24, 2023

    Nike & RTFKT Team Up To Bring Physical Air Force 1 NFT Sneakers To Collectors

    March 24, 2023

    NFT Trading Soars in Virtual Worlds: $311M in Q1 2023, Says DappRadar

    March 24, 2023

    ZED RUN x Budweiser: Web3 Collaboration You Can Wear

    March 24, 2023

    MVFW 2023: A Peek at the Four Fashion-Filled Days Ahead

    March 24, 2023

    L’Oréal’s Brandstorm Competition Brings You To The Metaverse

    March 23, 2023
    Get The FREE Exclusive Report
    CLICK HERE

    NFTevening is the biggest website for NFT news. We cover; breaking news, upcoming mints, plus, interviews with top NFT artists and projects. Put simply, we are the best place for new and experienced non-fungible token fans — making content fun & accessible

    Privacy policy
    Terms and conditions

    Article Categories
    • Blockchain games
    • Collectibles
    • Columns
    • Crypto Art
    • Guides
    • Interviews
    • Metaverse
    • Music
    • News
    • NFT Marketplaces and Tools
    • Sponsored Content
    • Top Blockchain Games
    • Top NFT Projects
    NFT Calendar
    • Today’s NFT Drops
    • Upcoming NFT Drops
    • Solana NFT Drops
    • NFT Calendar
    • NFT Calendar : Add Your NFT Event
    Get In Touch
    • Advertise (Media Kit)
    • Job Opportunities
    • About Us
    • Contact Us
    • Newsletter
    NFT Beginners Guides
    • How to Sell NFT Art
    • How to Create NFT Art
    • How to Display NFT Art
    • How To Make Passive Income With NFTs
    • Best Crypto Wallet
    • Best NFT Coins
    • Best NFT Rarity Tools
    • What is a DAO ?
    • What Are Crypto Gas Fees ?

    Type above and press Enter to search. Press Esc to cancel.