• bitcoinBitcoin (BTC) $ 97,929.00
  • ethereumEthereum (ETH) $ 3,422.48
  • tetherTether (USDT) $ 0.999834
  • xrpXRP (XRP) $ 2.28
  • bnbBNB (BNB) $ 673.37
  • solanaSolana (SOL) $ 191.75
  • dogecoinDogecoin (DOGE) $ 0.333996
  • usd-coinUSDC (USDC) $ 0.999898
  • cardanoCardano (ADA) $ 0.947731
  • staked-etherLido Staked Ether (STETH) $ 3,422.28
  • tronTRON (TRX) $ 0.250063
  • avalanche-2Avalanche (AVAX) $ 40.21
  • chainlinkChainlink (LINK) $ 23.55
  • wrapped-stethWrapped stETH (WSTETH) $ 4,085.83
  • the-open-networkToncoin (TON) $ 5.44
  • suiSui (SUI) $ 4.72
  • shiba-inuShiba Inu (SHIB) $ 0.000023
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 97,604.00
  • stellarStellar (XLM) $ 0.374559
  • polkadotPolkadot (DOT) $ 7.38
  • hyperliquidHyperliquid (HYPE) $ 33.17
  • hedera-hashgraphHedera (HBAR) $ 0.265818
  • wethWETH (WETH) $ 3,420.85
  • bitcoin-cashBitcoin Cash (BCH) $ 465.21
  • leo-tokenLEO Token (LEO) $ 9.27
  • uniswapUniswap (UNI) $ 13.74
  • pepePepe (PEPE) $ 0.000019
  • litecoinLitecoin (LTC) $ 103.05
  • wrapped-eethWrapped eETH (WEETH) $ 3,609.20
  • nearNEAR Protocol (NEAR) $ 5.31
  • bitget-tokenBitget Token (BGB) $ 4.25
  • ethena-usdeEthena USDe (USDE) $ 0.999907
  • aptosAptos (APT) $ 10.50
  • internet-computerInternet Computer (ICP) $ 10.76
  • usdsUSDS (USDS) $ 0.999845
  • aaveAave (AAVE) $ 318.11
  • crypto-com-chainCronos (CRO) $ 0.166702
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.498864
  • ethereum-classicEthereum Classic (ETC) $ 27.10
  • mantleMantle (MNT) $ 1.21
  • render-tokenRender (RENDER) $ 7.57
  • vechainVeChain (VET) $ 0.047964
  • mantra-daoMANTRA (OM) $ 3.94
  • bittensorBittensor (TAO) $ 483.31
  • moneroMonero (XMR) $ 192.11
  • whitebitWhiteBIT Coin (WBT) $ 24.47
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 1.35
  • ethenaEthena (ENA) $ 1.16
  • daiDai (DAI) $ 0.999781
  • arbitrumArbitrum (ARB) $ 0.795336
  • filecoinFilecoin (FIL) $ 5.19
  • kaspaKaspa (KAS) $ 0.124667
  • fantomFantom (FTM) $ 1.06
  • algorandAlgorand (ALGO) $ 0.352191
  • okbOKB (OKB) $ 45.83
  • cosmosCosmos Hub (ATOM) $ 6.97
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 2.68
  • blockstackStacks (STX) $ 1.78
  • ondo-financeOndo (ONDO) $ 1.79
  • optimismOptimism (OP) $ 1.88
  • bonkBonk (BONK) $ 0.000033
  • immutable-xImmutable (IMX) $ 1.45
  • celestiaCelestia (TIA) $ 5.30
  • theta-tokenTheta Network (THETA) $ 2.26
  • movementMovement (MOVE) $ 1.00
  • injective-protocolInjective (INJ) $ 22.12
  • the-graphThe Graph (GRT) $ 0.220958
  • dogwifcoindogwifhat (WIF) $ 2.12
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,422.75
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 97,946.00
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.030367
  • sei-networkSei (SEI) $ 0.450307
  • worldcoin-wldWorldcoin (WLD) $ 2.33
  • thorchainTHORChain (RUNE) $ 5.31
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,535.76
  • jasmycoinJasmyCoin (JASMY) $ 0.035351
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,833.46
  • flokiFLOKI (FLOKI) $ 0.000178
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.996574
  • gatechain-tokenGate (GT) $ 13.17
  • galaGALA (GALA) $ 0.038041
  • lido-daoLido DAO (LDO) $ 1.76
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,592.05
  • flare-networksFlare (FLR) $ 0.027887
  • tokenize-xchangeTokenize Xchange (TKX) $ 18.94
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 97,794.00
  • beam-2Beam (BEAM) $ 0.028430
  • makerMaker (MKR) $ 1,669.72
  • the-sandboxThe Sandbox (SAND) $ 0.590382
  • fasttokenFasttoken (FTN) $ 3.33
  • pyth-networkPyth Network (PYTH) $ 0.386577
  • usual-usdUsual USD (USD0) $ 1.00
  • nexoNEXO (NEXO) $ 1.37
  • solv-btcSolv Protocol SolvBTC (SOLVBTC) $ 97,876.00
  • tezosTezos (XTZ) $ 1.34
  • kaiaKaia (KAIA) $ 0.232544
  • kucoin-sharesKuCoin (KCS) $ 11.24
  • based-brettBrett (BRETT) $ 0.136258
  • raydiumRaydium (RAY) $ 4.58
  • eosEOS (EOS) $ 0.850955
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,516.93
  • heliumHelium (HNT) $ 7.05
  • binance-staked-solBinance Staked SOL (BNSOL) $ 195.83
  • ethereum-name-serviceEthereum Name Service (ENS) $ 36.62
  • aerodrome-financeAerodrome Finance (AERO) $ 1.65
  • jupiter-exchange-solanaJupiter (JUP) $ 0.873371
  • flowFlow (FLOW) $ 0.748420
  • xdce-crowd-saleXDC Network (XDC) $ 0.078341
  • starknetStarknet (STRK) $ 0.500687
  • arweaveArweave (AR) $ 17.12
  • iotaIOTA (IOTA) $ 0.311749
  • bitcoin-svBitcoin SV (BSV) $ 55.83
  • aioz-networkAIOZ Network (AIOZ) $ 0.965110
  • dydx-chaindYdX (DYDX) $ 1.54
  • bittorrentBitTorrent (BTT) $ 0.000001
  • curve-dao-tokenCurve DAO (CRV) $ 0.858939
  • msolMarinade Staked SOL (MSOL) $ 237.66
  • coredaoorgCore (CORE) $ 1.14
  • neoNEO (NEO) $ 14.64
  • axie-infinityAxie Infinity (AXS) $ 6.54
  • elrond-erd-2MultiversX (EGLD) $ 36.30
  • matic-networkPolygon (MATIC) $ 0.498275
  • decentralandDecentraland (MANA) $ 0.498351
  • solv-protocol-solvbtc-bbnSolv Protocol SolvBTC.BBN (SOLVBTC.BB) $ 97,192.00
  • apecoinApeCoin (APE) $ 1.22
  • fartcoinFartcoin (FARTCOIN) $ 0.849039
  • pendlePendle (PENDLE) $ 5.32
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 97,332.00
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,424.71
  • zcashZcash (ZEC) $ 54.52
  • eigenlayerEigenlayer (EIGEN) $ 3.99
  • mog-coinMog Coin (MOG) $ 0.000002
  • jito-governance-tokenJito (JTO) $ 3.07
  • chilizChiliz (CHZ) $ 0.089481
  • akash-networkAkash Network (AKT) $ 3.32
  • ai16zai16z (AI16Z) $ 0.725695
  • conflux-tokenConflux (CFX) $ 0.167135
  • wormholeWormhole (W) $ 0.284487
  • popcatPopcat (POPCAT) $ 0.802355
  • mina-protocolMina Protocol (MINA) $ 0.638598
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,423.20
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 204.71
  • usddUSDD (USDD) $ 1.00
  • compound-governance-tokenCompound (COMP) $ 84.46
  • roninRonin (RON) $ 1.97
  • superfarmSuperVerse (SUPER) $ 1.62
  • spx6900SPX6900 (SPX) $ 0.796863
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.49
  • havvenSynthetix Network (SNX) $ 2.12
  • ecasheCash (XEC) $ 0.000036
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,423.93
  • chiaChia (XCH) $ 22.00
  • dydxdYdX (ETHDYDX) $ 1.54
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.333431
  • gnosisGnosis (GNO) $ 267.57
  • dog-go-to-the-moon-runeDOG•GO•TO•THE•MOON (Runes) (DOG) $ 0.006939
  • amp-tokenAmp (AMP) $ 0.008191
  • peanut-the-squirrelPeanut the Squirrel (PNUT) $ 0.674733
  • axelarAxelar (AXL) $ 0.777406
  • zksyncZKsync (ZK) $ 0.185329
  • notcoinNotcoin (NOT) $ 0.006635
  • ether-fi-staked-btcEther.fi Staked BTC (EBTC) $ 96,937.00
  • chex-tokenCHEX Token (CHEX) $ 0.662540
  • layerzeroLayerZero (ZRO) $ 5.86
  • tether-goldTether Gold (XAUT) $ 2,629.15
  • fraxFrax (FRAX) $ 0.995284
  • baby-doge-coinBaby Doge Coin (BABYDOGE) $ 0.00000000
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 3,593.08
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000114
  • reserve-rights-tokenReserve Rights (RSR) $ 0.011611
  • grassGrass (GRASS) $ 2.51
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,702.76
  • vanaVana (VANA) $ 19.90
  • turboTurbo (TURBO) $ 0.008746
  • usualUsual (USUAL) $ 1.24
  • oasis-networkOasis (ROSE) $ 0.085602
  • blurBlur (BLUR) $ 0.274873
  • cat-in-a-dogs-worldcat in a dogs world (MEW) $ 0.006500
  • ordinalsORDI (ORDI) $ 27.47
  • safeSafe (SAFE) $ 1.11
  • 1inch1inch (1INCH) $ 0.404710
  • super-oethSuper OETH (SUPEROETHB) $ 3,419.31
  • echelon-primeEchelon Prime (PRIME) $ 11.03
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.35
  • goatseus-maximusGoatseus Maximus (GOAT) $ 0.538691
  • creditcoin-2Creditcoin (CTC) $ 1.31
  • beldexBeldex (BDX) $ 0.077287
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 97,904.00
  • susdssUSDS (SUSDS) $ 1.02
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • livepeerLivepeer (LPT) $ 14.41
  • apenftAPENFT (NFT) $ 0.00000053
  • pax-goldPAX Gold (PAXG) $ 2,623.49
  • gigachad-2Gigachad (GIGA) $ 0.053640
  • pumpbtcpumpBTC (PUMPBTC) $ 96,893.00
  • kusamaKusama (KSM) $ 32.45
  • arkhamArkham (ARKM) $ 1.55
  • nervos-networkNervos Network (CKB) $ 0.011268
  • dexeDeXe (DEXE) $ 9.20
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 3,419.57

ERC-2771 integration introduces address spoofing vulnerability — OpenZeppelin

0 187

ERC-2771 integration introduces address spoofing vulnerability — OpenZeppelin

  cointelegraph.com 08 December 2023 08:27, UTC

ERC-2771 integration introduces address spoofing vulnerability — OpenZeppelin

Soon after Thirdweb revealed a security vulnerability that could impact a variety of common smart contracts used across the Web3 ecosystem, OpenZeppelin identified two specific standards as the root cause of the threat.

On Dec. 4, Thirdweb reported a vulnerability in a commonly used open-source library, which could impact pre-built contracts, including DropERC20, ERC-721, ERC-1155 (all versions) and AirdropERC20.

In response, smart contracts development platform OpenZepplin and nonfungible token marketplaces Coinbase NFT and OpenSea proactively informed users about the threat. Upon further investigation, OpenZepplin found that the vulnerability stems from “a problematic integration of two specific standards: ERC-2771 and Multicall.”

The smart contract vulnerability in question arises after the integration of ERC-2771 and multicall standards. OpenZepplin identified 13 sets of vulnerable smart contracts, as shown below. However, crypto service providers are advised to address the issue before bad actors find a way to exploit the vulnerability.

ERC-2771 integration introduces address spoofing vulnerability — OpenZeppelin

Smart contract vulnerabilities linked to ERC-2771 integration. Source: Thirdweb

OpenZepplin’s investigation found that the ERC-2771 standard allows overriding certain call functions. This could be exploited to extract the sender’s address information and spoof calls on their behalf.

ERC-2771 integration introduces address spoofing vulnerability — OpenZeppelin

An attacker can potentially wrap multiple spoofed calls within a single multicall(bytes[]). Source: OpenZeppelin

OpenZepplin advised the Web3 community using the aforementioned integrations to use a 4-step method for ensuring safety: disable every trusted forwarder, pause contract and revoke approvals, prepare an upgrade and evaluate snapshot options.

In addition, Thirdweb launched a mitigation tool that allows users to connect their wallets and identify if a contract is vulnerable.

The decentralized finance platform Velodrome also deactivated its relay services until a new version was installed.

In a recent Cointelegraph Magazine article, experts revealed how artificial intelligence (AI) can help audit smart contracts and aid cybersecurity efforts.

James Edwards, the lead maintainer for cybersecurity investigator Librehash, said that while AI chatbots can develop smart contracts, deploying them in a live environment is risky.

On the other hand, Edwards highlighted the technology’s potential to vet smart contracts. Recent tests showed AI’s ability to “audit contracts with an unprecedented amount of accuracy that far surpasses what one could expect and would receive from GPT-4.”

While he concedes it’s not as good as a human auditor yet, it can already do a strong first pass to speed up the auditor’s work and make it more comprehensive.

Source

Leave A Reply

Your email address will not be published.