All Stolen Bored Ape and Mutant Ape NFTs Returned After Bounty Payment
All Bored Ape Yacht Club (BAYC) and Mutant Ape Yacht Club (MAYC) nonfungible tokens (NFTs) that were stolen from NFT Trader have been returned after a bounty payment. The hack occurred on December 16, resulting in the theft of NFTs worth nearly $3 million. The attacker attributed the exploit to another user and demanded ransom payments for the return of the NFTs. However, a community initiative led by Boring Security was able to recover all the assets within 24 hours by paying a 120 ETH bounty, equivalent to around $267,000. The Boring Security team confirmed that they now have possession of all the stolen NFTs.
Bounty Paid by Yuga Labs Co-Founder
The bounty payment of 120 ETH was made by Greg Solano, co-founder of Yuga Labs, the creator of the stolen NFT collections. Yuga Labs supported negotiations to retrieve the tokens and return them to their original owners free of charge.
Vulnerability Found in Smart Contract Upgrade
The vulnerability that allowed the exploit to occur was introduced during a smart contract upgrade around 11 days ago. This upgrade enabled unauthorized transfers of NFTs due to previously granted trading permissions. The developer known as “Foobar” assisted NFT Trader’s team in stopping the attack after it was discovered. Foobar emphasized the importance of revoking all permissions granted to two old contracts (0xc310e760778ecbca4c65b6c559874757a4c4ece0 and 0x13d8faF4A690f5AE52E2D2C52938d1167057B9af) to prevent future thefts.
Hot Take: Boring Security Initiative Successfully Recovers Stolen NFTs
The quick action taken by the Boring Security initiative, funded by ApeCoin, successfully recovered all the stolen Bored Ape and Mutant Ape NFTs. By paying a bounty and working together as a community, the NFTs were returned to their rightful owners. This incident highlights the importance of security measures and continuous monitoring in the crypto space to prevent unauthorized access and theft. It also demonstrates the power of collective action in addressing security breaches and recovering stolen assets. The successful resolution of this hack serves as a positive example for the crypto community in combating cybercrime and protecting valuable digital assets.