{"id":35161,"date":"2022-09-05T06:08:55","date_gmt":"2022-09-05T10:08:55","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=35161"},"modified":"2022-09-05T06:09:03","modified_gmt":"2022-09-05T10:09:03","slug":"nft-watchdog-rug-pull-finder-has-its-nft-giveaway-hacked","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/nft-watchdog-rug-pull-finder-has-its-nft-giveaway-hacked\/","title":{"rendered":"NFT watchdog Rug Pull Finder has its NFT giveaway hacked"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\">Two con artists were able to mint 450 NFTs instead of one per wallet because of misuse of the Rug Pull Finder NFT contract.<\/h5>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/09\/MA-011419-HACKER-Popup1-1024x683.jpg\" alt=\"NFT watchdog Rug Pull Finder has its NFT giveaway hacked\" class=\"wp-image-35169\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/09\/MA-011419-HACKER-Popup1-1024x683.jpg 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/09\/MA-011419-HACKER-Popup1-300x200.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/09\/MA-011419-HACKER-Popup1-768x512.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/09\/MA-011419-HACKER-Popup1-150x100.jpg 150w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/09\/MA-011419-HACKER-Popup1-750x500.jpg 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/09\/MA-011419-HACKER-Popup1-1140x760.jpg 1140w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/09\/MA-011419-HACKER-Popup1.jpg 1200w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>NFT watchdog Rug Pull Finder has its NFT giveaway hacked<\/figcaption><\/figure>\n\n\n\n<p>In an ironic turn of events, Rug Pull Finder (RPF),<a href=\"https:\/\/coinscreed.com\/staging\/after-185k-nft-charity-auction-hacker-steals-bill-murrays-crypto.html\" target=\"_blank\" rel=\"noreferrer noopener\"> a nonfungible token (NFT) <\/a>watchdog dedicated to exposing Web3-based fraud, was itself the victim of a smart contract flaw.<\/p>\n\n\n\n<p>Two individuals stole 450 NFTs out of a possible 1,221 that were supposed to be limited to one per wallet due to a technical defect in the project, according to the NFT investigator's post on Twitter on September 2.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">As discussed on our Twitter space&#39;s earlier today &#8211; <br><br>We messed up. We messed up big. Our contract had a flaw that allowed 2 people to scoop up over 450 NFTs.<br><br>Here is what we are doing to fix it \ud83e\uddf5<\/p>&mdash; Rug Pull Finder (@rugpullfinder) <a href=\"https:\/\/twitter.com\/rugpullfinder\/status\/1565791659928977408?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">September 2, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>RPF claims that its smart contract had a bug that allowed code to be abused, enabling the bandits to give themselves access to more NFTs than was permitted.<\/p>\n\n\n\n<p>The <a href=\"https:\/\/www.google.com\/search?q=NFT+watchdog+Rug+Pull+Finder+has+its+NFT+giveaway+hacked&oq=NFT+watchdog+Rug+Pull+Finder+has+its+NFT+giveaway+hacked&aqs=chrome..69i57j33i160.780j0j9&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noreferrer noopener\">RPF team<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> took action to address the issue shortly after the exploit, making an offer to one of the parties involved to pay them a bounty of 2.5 ETH (worth $3,944.68 at the time of writing) in exchange for finding 330 of the NFTs. This offer was accepted.<\/p>\n\n\n\n<p>The exploiters &#8220;did negotiate in good faith and allowed us to get to an acceptable arrangement with them,&#8221; according to the crypto detectives.<\/p>\n\n\n\n<p>The &#8220;Bad Guys&#8221; free mint included artwork created by <a href=\"https:\/\/coinscreed.com\/staging\/crypto-scammers-hack-s-korean-govts-youtube-channel.html\" target=\"_blank\" rel=\"noreferrer noopener\">NFT &#8220;scammers<\/a> mistakenly let wild on the network.&#8221;<\/p>\n\n\n\n<p>Prior to the impending 10,000 NFT collection this fall, the collection serves as a whitelist or presale for members.<\/p>\n\n\n\n<p>Exclusive access to the mint, the RPF major drop, and other forthcoming projects is available when holding a bad guy NFT.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-alerts-disregarded\">Alerts disregarded<\/h2>\n\n\n\n<p>The monitoring group said that the attack happened because they disregarded warnings about the bug supplied by an unidentified source 30 minutes before the mint went live.<\/p>\n\n\n\n<p>&#8220;After reviewing it with three different dev teams, we did not believe the credibility of the information sent to us&#8230; We were clearly wrong, and we are truly, truly sorry,&#8221; RPF said.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">As discussed on our Twitter space&#39;s earlier today &#8211; <br><br>We messed up. We messed up big. Our contract had a flaw that allowed 2 people to scoop up over 450 NFTs.<br><br>Here is what we are doing to fix it \ud83e\uddf5<\/p>&mdash; Rug Pull Finder (@rugpullfinder) <a href=\"https:\/\/twitter.com\/rugpullfinder\/status\/1565791659928977408?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">September 2, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Doxxed Media, a digital blockchain creative studio, was cited by the <a href=\"https:\/\/coinscreed.com\/staging\/after-185k-nft-charity-auction-hacker-steals-bill-murrays-crypto.html\" target=\"_blank\" rel=\"noreferrer noopener\">NFT investigator<\/a> as having handled all of the contract and artwork, and it acknowledged that it &#8220;did not have our team audit it, or an independent 3rd party.&#8221;<\/p>\n\n\n\n<p>The irony of the exploit has not escaped the attention of the cryptocurrency community, with some applauding the NFT investigator for admitting its mistake while others have questioned why a business that specializes in finding smart contract vulnerabilities didn't perform the necessary checks on its own project.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">I think its concerning when security minded projects like RugPullFinder get their discord breached and their code exploited yet they&#39;re offering those exact services to customers. What do you think? <a href=\"https:\/\/t.co\/zJRWUXqic5\" target=\"_blank\">pic.twitter.com\/zJRWUXqic5<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; okHOTSHOT (@NFTherder) <a href=\"https:\/\/twitter.com\/NFTherder\/status\/1565775618968543233?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">September 2, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Despite the rocky beginning, RPF was able to restart its NFT project.<\/p>\n\n\n\n<p>RPF has chosen to disperse the recovered <a href=\"https:\/\/coinscreed.com\/staging\/free-nft-licensing-system-declares-andreessen-horowitz.html\" target=\"_blank\" rel=\"noreferrer noopener\">NFTs<\/a> in a number of places after consulting with their online community, including the &#8220;Bad Guys Vault,&#8221; a Twitter raffle, two further raffles for projects that are friends of Rug Pull Finder, and the Rug Pull Finder public sale wallet collection list.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Two con artists were able to mint 450 NFTs instead of one per wallet because of misuse of the Rug Pull Finder NFT contract. In an ironic turn of events, Rug Pull Finder (RPF), a nonfungible token (NFT) watchdog dedicated to exposing Web3-based fraud, was itself the victim of a smart contract flaw. Two individuals [&hellip;]<\/p>\n","protected":false},"author":38,"featured_media":35169,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[1496,470,11257],"class_list":["post-35161","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-hack","tag-nfts","tag-rug-pull-finder"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/09\/MA-011419-HACKER-Popup1.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/35161","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/38"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=35161"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/35161\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/35169"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=35161"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=35161"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=35161"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}