DeFi detective alleges this ‘suspicious’ smart contract code may put dozens of projects at risk

According to famed decentralized finance (DeFi) detective Zachxbt, 31 nonfungible token (NFT) projects may be at risk due to “suspicious code.” In a lengthy Twitter thread published Tuesday, the DeFi detective first raised the issue of NFT project Thestarlab, which was allegedly compromised for 197.175 Ether (ETH), worth $580,325 at the time of publication. Zachxbt quoted fellow blockchain investigator MouseDev, who came to the following conclusion after reviewing the code behind Thestarlab: 

“The smart contract [for this project] can never truly be renounced or transferred-only an additional owner. The original deployer will always be considered the owner. This means if they still have the private key of the deployer, they can pull the money, even though the owner is the null address.”

MouseDev claimed that when the projects’ developers deployed their contract, they stored two variables as the owner. “Then they later changed one of them to the null address to appear as though they relinquished but kept another unchanged variable,” said MouseDev.

Based on this information, Zachxbt claimed to have uncovered 31 NFT projects that all contracted the same Fiverr developer to deploy the allegedly problematic smart contract. Additionally, the DeFi detective had the following remarks:

“Please do proper due diligence. Always review the contract beforehand, especially if outsourced. Luckily, since then a few of the projects were able migrate contracts and confront the Fiver dev. After reviewing internally, a few found other red flags as well.”

All Dutch and English crypto news!

Bitcoin price loses $60K support to hit 2-month lows

Bitcoin traders feel the sting of $160 million liquidations as BTC price returns to levels not seen since February. Market Update Own this piece of crypto history Collect...

World of Dypians Offers Up to 1M $WOD and $225,000 in Premium Subscriptions via the BNB Chain Airdrop Alliance Program

Tortola, BVI, May 1st, 2024, Chainwire World of Dypians (WOD) – an immersive, revolutionary MMORPG available on Epic Games, is on an exclusive list of top-tier...

EigenLayer sees over 12,000 queued withdrawals. How far will TVL fall?

Mass withdrawals started on April 29, after EigenLayer's decision to ban U.S. and Canada-based participants from its upcoming airdrop. News Own this piece of crypto history Collect this...

Nigeria restricts fintech onboarding to stop KYC-evading crypto investors

Nigerian fintech firms OPay, Kuda Bank, Moniepoint and PalmPay were directed to pause the creation of new accounts amid an ongoing audit of their KYC...

Beste exchanges

Koop je crypto bij Bitvavo