{"id":21638,"date":"2022-03-23T14:13:20","date_gmt":"2022-03-23T13:13:20","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=21638"},"modified":"2022-03-23T14:13:31","modified_gmt":"2022-03-23T13:13:31","slug":"veve-nft-market-shuts-down-after-an-exploit","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/veve-nft-market-shuts-down-after-an-exploit\/","title":{"rendered":"Veve NFT marketplace temporarily shuts down after an in-app token exploit"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\"><a href=\"https:\/\/coinscreed.com\/staging\/pixar-pals-nft-collection-sells-out-within-24-hours-of-its-launch-on-veve.html\" target=\"_blank\" data-type=\"post\" data-id=\"20875\" rel=\"noreferrer noopener\">Veve, a nonfungible token (NFT) marketplace<\/a> to brands such as Marvel, Pixar, and Coca-Cola was hit by an attack on Tuesday, resulting in the illicit acquisition of millions of gems (in-app tokens). <\/h5>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/image-159-1024x550.png\" alt=\"Veve NFT marketplace temporarily shuts down after an in-app token exploit\" class=\"wp-image-21639\" width=\"953\" height=\"512\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/image-159-1024x550.png 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/image-159-300x161.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/image-159-768x412.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/image-159-150x81.png 150w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/image-159-750x403.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/image-159.png 1054w\" sizes=\"(max-width: 953px) 100vw, 953px\" \/><figcaption>Veve NFT marketplace temporarily shuts down after an in-app token exploit<\/figcaption><\/figure><\/div>\n\n\n\n<p>Veve acknowledged the breach on its platform in an official tweet released on Wednesday, saying that the attackers were able to obtain a &#8220;significant amount&#8221; of gems illegally. Until the inquiry is completed, <a href=\"https:\/\/www.google.com\/search?q=Veve+NFT+marketplace+temporarily+shuts+down+after+an+in-app+token+exploit&rlz=1C1SQJL_enNG889NG889&oq=Veve+NFT+marketplace+temporarily+shuts+down+after+an+in-app+token+exploit&aqs=chrome..69i57.1002j0j9&sourceid=chrome&ie=UTF-8\" target=\"_blank\" data-type=\"URL\" data-id=\"https:\/\/www.google.com\/search?q=Veve+NFT+marketplace+temporarily+shuts+down+after+an+in-app+token+exploit&rlz=1C1SQJL_enNG889NG889&oq=Veve+NFT+marketplace+temporarily+shuts+down+after+an+in-app+token+exploit&aqs=chrome..69i57.1002j0j9&sourceid=chrome&ie=UTF-8\" rel=\"noreferrer noopener\">the app-based NFT platform<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> has taken down the marketplace as well as the gems buying option.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">As a result of this exploit, we have closed the Market, Gem purchases and transfers while we investigate. We will update you on the expected timing of Market opening as soon as we can.<\/p>&mdash; VeVe | Digital Collectibles (@veve_official) <a href=\"https:\/\/twitter.com\/veve_official\/status\/1506462178223616001?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">March 23, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Gems are the VeVe in-app currency that users may swap for collectibles in the Market or during drops. According to early reports, the attackers were able to create millions of gems without having to pay for them by exploiting a flaw in the purchase system.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Twitter users complain about the exploit\u00a0<\/h2>\n\n\n\n<p>One user said that a friend bought gems with an expired <a href=\"https:\/\/coinscreed.com\/staging\/american-express-is-exploring-ways-to-allow-credit-cardholders-to-redeem-points-for-crypto-ceo.html\" target=\"_blank\" data-type=\"post\" data-id=\"17215\" rel=\"noreferrer noopener\">credit card<\/a> and that the transaction went through.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">From what I heard someone was informed by their friend they accidentally purchased gems with an expired credit card and the transaction went through anyway. So it sounds more like an expired credit card exploit than stolen credit cards. No confirmation by Veve yet though.<\/p>&mdash; \ud83c\uddfa\ud83c\udde6\u2b55Garlic Shrimp\u2b55\ud83c\uddfa\ud83c\udde6\ud83e\uddc4 \ud83e\udd90 (@GARLICxSHRIMP) <a href=\"https:\/\/twitter.com\/GARLICxSHRIMP\/status\/1506319537335148544?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">March 22, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Several user accounts have also been suspended when it was discovered that they were attempting to purchase cheap gems from bogus accounts.<\/p>\n\n\n\n<p>While the<a href=\"https:\/\/coinscreed.com\/staging\/nft-platform-rarible-introduces-a-zero-cost-fee-for-minting-nfts.html\" target=\"_blank\" data-type=\"post\" data-id=\"12422\" rel=\"noreferrer noopener\"> NFT platform<\/a> did not reveal the actual number of gems abused, a Twitter user said the sum may be in the millions, making it the site's greatest robbery. At the time of publication.<\/p>\n\n\n\n<p>The Twitter user also revealed a chronology of the exploit's actions, which included Veve registering the greatest 3-day buying of in-app token gems, followed by a 50% drop in the price of the token from 0.5 to 0.25, and the marketplace going into maintenance.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Soooo&#8230;. <br><br>apparently about 7M gems were fraudly purchased<br><br>Multiple accounts that interacted with them are now disabled <br><br>Veve will need to recover those gems and this will be their biggest exploit to date \ud83d\ude2c<br><br>Users that purchased cheap gems off app will likely lose funds \ud83e\udd26 <a href=\"https:\/\/t.co\/7YG3BBXjMe\" target=\"_blank\">https:\/\/t.co\/7YG3BBXjMe<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; Nifty \ud83c\udf4e (@niftymfer) <a href=\"https:\/\/twitter.com\/niftymfer\/status\/1506462559893069826?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">March 23, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>The gem vulnerabilities on Veve also led to a large drop in the price of the platform's listed NFTs, with one user realizing why his NFT value had dropped by 80% just a week after Veve's official Twitter tweet.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/veve_official?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@veve_official<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> just saw your latest tweet, now I understand why my secret rare goofy dropped 80% in value from the ATH at Market in a matter of weeks and I panic sold it finally. Very unhappy! 1st BOTS and now Gem exploit???<\/p>&mdash; Jai S (@jai_sond) <a href=\"https:\/\/twitter.com\/jai_sond\/status\/1506525526588022788?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">March 23, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>Veve, a nonfungible token (NFT) marketplace to brands such as Marvel, Pixar, and Coca-Cola was hit by an attack on Tuesday, resulting in the illicit acquisition of millions of gems (in-app tokens). Veve acknowledged the breach on its platform in an official tweet released on Wednesday, saying that the attackers were able to obtain a [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":21639,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21,62],"tags":[8271,8272,8270,8046,6133],"class_list":["post-21638","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-nft-news","tag-expliot","tag-in-app-tokens","tag-marvel-2","tag-nft-marketplace-2","tag-veve"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/image-159.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/21638","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=21638"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/21638\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/21639"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=21638"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=21638"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=21638"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}