{"id":66271,"date":"2023-12-05T05:01:48","date_gmt":"2023-12-05T09:01:48","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=66271"},"modified":"2023-12-05T05:01:52","modified_gmt":"2023-12-05T09:01:52","slug":"thirdweb-discloses-common-security-flaw-in-smart-contracts","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/thirdweb-discloses-common-security-flaw-in-smart-contracts\/","title":{"rendered":"Thirdweb Discloses Common Security Flaw in Smart Contracts"},"content":{"rendered":"\n<p>Thirdweb, a Web3 firm that develops smart contracts, has disclosed a security flaw that &#8220;may affect an assortment of smart contracts throughout the <a href=\"https:\/\/coinscreed.com\/staging\/rise-of-decentralized-gaming-platforms-in-the-web3-ecosystem.html\" target=\"_blank\" rel=\"noreferrer noopener\">Web3 ecosystem<\/a>.&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"941\" height=\"572\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/image-9.png\" alt=\"Thirdweb Discloses Common Security Flaw in Smart Contracts\" class=\"wp-image-66276\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/image-9.png 941w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/image-9-300x182.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/image-9-768x467.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/image-9-18x12.png 18w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/image-9-750x456.png 750w\" sizes=\"(max-width: 941px) 100vw, 941px\" \/><figcaption class=\"wp-element-caption\">Thirdweb Discloses Common Security Flaw in Smart Contracts<\/figcaption><\/figure>\n\n\n\n<p>Thirdweb disclosed a vulnerability in a widely utilized open-source library on December 4, which had the potential to affect particular pre-built smart contracts, including some that it had developed. <\/p>\n\n\n\n<p>Nonetheless, Thirdweb's investigations have determined that the smart contract vulnerability remains untouched, providing <a href=\"https:\/\/coinscreed.com\/staging\/insomnia-labs-partners-with-web3-firms-for-brand-loyalty-shift.html\" target=\"_blank\" rel=\"noreferrer noopener\">Web3 firms <\/a>with a limited time to avert a potential intrusion.<\/p>\n\n\n\n<p>Thirdweb stated, emphasizing the vulnerability's potential to cause catastrophic damage if not remedied immediately:<\/p>\n\n\n\n<p><em>\u201cThe impacted pre-built contracts include but are not limited to DropERC20, ERC721, ERC1155 (all versions), and AirdropERC20.\u201d<\/em><\/p>\n\n\n\n<p>The company proactively warned users who had deployed its contracts before November 22. These users were advised to &#8220;take mitigation steps&#8221; either independently or by utilizing a tool provided by the company.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">IMPORTANT <br><br>On November 20th, 2023 6pm PST, we became aware of a security vulnerability in a commonly used open-source library in the web3 industry.<br><br>This impacts a variety of smart contracts across the web3 ecosystem, including some of thirdweb\u2019s pre-built smart contracts.\u2026<\/p>&mdash; thirdweb (@thirdweb) <a href=\"https:\/\/twitter.com\/thirdweb\/status\/1731841493407576247?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">December 5, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Thirdweb also recommended that developers assist users in rescinding approvals on all impacted contracts through revoke.cash. &#8220;This will safeguard your users if you opt not to mitigate the contract,&#8221; DefiLlama developer &#8220;0xngmi&#8221; added in response to the request to revoke approvals.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">btw this seems important, theyre asking to revoke all approvals to third web contracts (you might have interacted with them without knowing as theyre white-labelled, especially if you do stuff around nfts) <a href=\"https:\/\/t.co\/T1YU9xnIRb\" target=\"_blank\">https:\/\/t.co\/T1YU9xnIRb<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; 0xngmi is hiring (@0xngmi) <a href=\"https:\/\/twitter.com\/0xngmi\/status\/1731889230387814893?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">December 5, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Thirdweb has initiated communication with the maintainers of the <a href=\"https:\/\/www.heavy.ai\/technical-glossary\/open-source-library\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">open-source library <span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>that contains the critical flaw and with other teams that may be affected by the situation.<\/p>\n\n\n\n<p>It also promised to implement a more stringent auditing procedure and increase funding for security measures and bug bounty payments by twofold, from $25,000 to $50,000. Additionally, the company provided a grant to address contract mitigations.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>\u201cWe understand that this will cause disruption, and we are treating the mitigation of the issue with the utmost seriousness. We will be offering a retroactive gas grant to cover fees for contract mitigations.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p>For security purposes, complete information regarding the vulnerability was withheld. <\/p>\n\n\n\n<p>In August 2022, the company secured $24 million in<a href=\"https:\/\/coinscreed.com\/staging\/game-developer-neon-machine-raises-20m-in-series-a-funding.html\" target=\"_blank\" rel=\"noreferrer noopener\"> Series A funding <\/a>from Haun Ventures, Coinbase, Shopify, and Polygon.<\/p>\n\n\n\n<p>Monthly usage of the Web3 company's multichain smart contract deployment tools for gaming, minting, marketplaces, and wallets is reportedly over 70,000 developers.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Thirdweb, a Web3 firm that develops smart contracts, has disclosed a security flaw that &#8220;may affect an assortment of smart contracts throughout the Web3 ecosystem.&#8221; Thirdweb disclosed a vulnerability in a widely utilized open-source library on December 4, which had the potential to affect particular pre-built smart contracts, including some that it had developed. Nonetheless, [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":66276,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[17468,1886,14826,6795],"class_list":["post-66271","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-security-flaw","tag-smart-contracts","tag-thirdweb","tag-web3-2"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/12\/image-9.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/66271","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=66271"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/66271\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/66276"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=66271"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=66271"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=66271"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}