Unveiling a Significant Security Vulnerability Found in Widely Used Smart Contracts by Web3 Company

Unveiling a Significant Security Vulnerability Found in Widely Used Smart Contracts by Web3 Company


Smart Contract Development Firm Discovers Security Vulnerability

Thirdweb, a smart contract development firm, has uncovered a security vulnerability that could potentially impact various smart contracts within the Web3 ecosystem. The vulnerability was found in a widely used open-source library and could affect specific pre-built smart contracts, including Thirdweb’s own contracts. While the vulnerability has not been exploited yet, Thirdweb has issued a warning to Web3 firms to address the issue promptly.

Potential for Massive Damage

The vulnerability has the potential to cause significant damage if left unresolved. It affects several pre-built contracts such as DropERC20, ERC721, ERC1155, and AirdropERC20. Thirdweb urges users who deployed its contracts before November 22 to take immediate mitigation steps using either their own tools or a tool provided by the company.

Developers Advised to Revoke Approvals

Thirdweb also recommends that developers help users revoke approvals on all affected contracts using revoke.cash. This step will protect users in case they choose not to mitigate the contract vulnerabilities.

Increased Investment in Security Measures

To address the issue and prevent future vulnerabilities, Thirdweb has contacted the maintainers of the open-source library and other potentially impacted teams. The company plans to increase its investment in security measures and double bug bounty payouts from $25,000 to $50,000. They will also implement a more rigorous auditing process and offer a grant to cover contract mitigations.

About Thirdweb

Thirdweb is a Web3 company that provides smart contract deployment tools for gaming, minting, marketplaces, and wallets. They recently raised $24 million in a Series A funding round with support from Haun Ventures, Coinbase, Shopify, and Polygon. With over 70,000 developers using their services monthly, Thirdweb plays a significant role in the Web3 ecosystem.

Hot Take: Security Vulnerability Discovered in Web3 Smart Contracts

Read Disclaimer
This page is simply meant to provide information. It does not constitute a direct offer to purchase or sell, a solicitation of an offer to buy or sell, or a suggestion or endorsement of any goods, services, or businesses. Lolacoin.org does not offer accounting, tax, or legal advice. When using or relying on any of the products, services, or content described in this article, neither the firm nor the author is liable, directly or indirectly, for any harm or loss that may result. Read more at Important Disclaimers and at Risk Disclaimers.

Smart contract development firm Thirdweb has identified a security vulnerability that poses a risk to various smart contracts within the Web3 ecosystem. The vulnerability, found in a widely used open-source library, could potentially be exploited to cause significant damage. However, no exploits have been reported at this time, giving Web3 firms an opportunity to address the issue proactively. Thirdweb has advised users to take mitigation steps and revoke approvals on affected contracts. They have also reached out to the library maintainers and other impacted teams. To enhance security measures, Thirdweb plans to increase investment, double bug bounty payouts, and implement stricter auditing processes.

Author – Contributor at | Website

Coinan Porter stands as a notable crypto analyst, accomplished researcher, and adept editor, carving a significant niche in the realm of cryptocurrency. As a skilled crypto analyst and researcher, Coinan’s insights delve deep into the intricacies of digital assets, resonating with a wide audience. His analytical prowess is complemented by his editorial finesse, allowing him to transform complex crypto information into digestible formats.