Mahi Sall, Advisor, Fintech-Bank Partnerships, Payments and Financial Inclusivity
January 25th, 2023
Yahoo Finance | Sean Dickens | Jan 24, 2022
An API issue on popular NFT marketplaces OpenSea and Rarible has led to NFT collectors incurring massive losses on their prized Bored Apes and Cool Cats.
The error was caused by NFT collectors incorrectly cancelling their listings on OpenSea by opting to transfer their assets to another wallet in an attempt to avoid paying cancellation fees, which can fetch up to $100 based on gas prices.
This method was assumed to have ‘cancelled’ the listing as it no longer showed as ‘listed’ on the front end of OpenSea’s user interface.However, the listings were still accessible as older ‘listings’ on alternative marketplace Rarible, which uses data from the OpenSea API to list and display NFTs for sale.
Over time, collectors began transferring their NFTs back to the original wallet. Now, unbeknownst to them, their prized assets were again purchasable for unbelievably low prices as the listings were still ‘valid’ on Rarible.
As collectors began to transfer their NFTs back to the original wallet, the listings remained ‘open’ on Rarible as the blockchain still recognised that the NFT was listed at the original listing price.
However, collectors still began losing their prized assets for unbelievably low prices as the OpenSea front end showed that the listings had been cancelled and were no longer available, meaning that they remained oblivious that their prized assets were still purchasable, leading to catastrophic losses for a select few.
The exploit started early this morning with a number of below-market-value purchases from OpenSea user ‘jpegdegenlove‘ for three Bored Apes, two Mutant Apes, a Cool Cat and a Genesis CyberKongz NFT.
It’s now believed that the exploiter interacted directly with smart contracts to ‘bypass’ the OpenSea interface and discover the listings that were still available for purchase ‘on-chain’ – thus making them purchasable without the holders being aware.
The person behind the exploit, ‘jpegdegenlove’, has managed to gain around 332 ETH ($737k) following the exploit
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
Support NCFA by Following us on Twitter!Follow @NCFACanada |
January 25th, 2023
June 1st, 2021
September 9th, 2020
July 17th, 2020
August 22nd, 2019
September 26th, 2018
July 9th, 2018
March 19th, 2018
January 3rd, 2018
September 25th, 2017
July 31st, 2017
June 20th, 2017
May 10th, 2017
May 9th, 2017
December 14th, 2016
September 13th, 2016
NCFA Canada
Craig Asano
CEO and Executive Director
casano@ncfacanada.org
ncfacanada.org
Leave a Reply