DeFi detective alleges this 'suspicious' smart contract code may put dozens of projects at risk

Published at: March 8, 2022

According to famed decentralized finance, or DeFi, detective zachxbt, 31 nonfungible-tokens, or NFTs, projects may be at risk due to "suspicious code." In a lengthy Twitter thread published Tuesday, the DeFi detective first raised the issue of NFTs project Thestarlab — which was allegedly compromised for 197.175 Ether (ETH), worth $580,325 USD at time of publication. Zachxbt quoted fellow blockchain investigator _MouseDev, who came to the following conclusion after reviewing the code behind Thestarlab: 

"The smart contract [for this project] can never truly be renounced or transferred—only an additional owner. The original deployer will always be considered the owner. This means if they still have the private key of the deployer, they can pull the money, even though the owner is the null address."

_MouseDev claimed that when the projects' developers deployed their contract, they stored two variables as the owner. "Then they later changed one of them to the null address to appear as though they relinquished but kept another unchanged variable," says _MouseDev.

Based on this information, zachxbt claimed to have uncovered 31 NFTs projects that all contracted the same Fiverr developer to deploy the allegedly problematic smart contract. Additionally, the DeFi detective had the following remarks:

"Please do proper due diligence. Always review the contract beforehand, especially if outsourced. Luckily, since then a few of the projects were able migrate contracts and confront the Fiver dev. After reviewing internally, a few found other red flags as well."

1/ Recently a NFT project wascompromised rugging the team of197 ETH. Interestingly enough,suspicious code lay within thesmart contract potentially putting31 other NFT projects at risk. Howis this possible you ask? Well let'sdive in. pic.twitter.com/NelTIkoNVm

— zachxbt (@zachxbt) March 8, 2022
Tags
Nft
Related Posts
Top 7 blockchain courses and certifications for beginners
Blockchain courses and certifications can play an important role in helping individuals gain a comprehensive understanding of blockchain technology and its applications. By completing these courses, individuals can develop technical skills, stay current with industry developments, enhance their career opportunities and increase their earning potential. Here are seven blockchain courses and certifications for beginners. INE’s Blockchain Security INE’s Blockchain Security course is an online course offered by Internetwork Expert (INE) that provides a comprehensive overview of the security aspects of blockchain technology. The course covers various topics such as consensus algorithms, cryptography, network security, smart contract security, and blockchain attacks …
Decentralization / Feb. 2, 2023
Supply chain tokens see triple-digit gains as the global economy recovers
Over the last few weeks, blockchain projects focused on supply chains and logistics have seen tremendous growth as the coronavirus-induced economic gridlock begins to loosen and future concerns related to the global pandemic subside. Three logistics projects that have benefited from the improving economic outlook are OriginTrail, Waltonchain and Wabi. Since early February, each has seen its token price increase by up to 300%. TRAC/USD OriginTrail is a self-described “ecosystem dedicated to making global supply chains work together by enabling a universal, collaborative and trusted data exchange.” The project was established in 2011 with the goal of providing enterprise users …
Technology / March 15, 2021
Mark Cuban issues burn notice on offensive ENS domain
Someone sent Mark Cuban a profane Ethereum Name Service domain a few days ago. After observant Twitter users recently tracked down his ether address, it was only a matter of time before a wave of unwanted spam transactions made their way into his account. This is, after all, the internet. Here there be monsters. While it isn’t entirely clear what the presumed troll’s endgame was, the word was nonetheless offensive enough to raise some eyebrows at Cointelegraph, and we don’t intend to reprint it here. Suffice to say, a decent person would not want to be known as the owner …
Technology / Feb. 3, 2021
3 things the crypto sector must offer to truly mainstream with TradFi
In the past year, we’ve seen the crypto economy undergo exponential expansion as heaps of money poured into various cryptocurrencies, decentralized finance (DeFi), nonfungible tokens (NFT), crypto indices, insurance products and decentralized options markets. The total value locked (TVL) in the DeFi sector across all chains has grown from $18 billion at the beginning of 2021 to $240 billion in January 2022. With so much liquidity in the ecosystem, the crypto lending space has also grown a significant amount, from $60 million at the beginning of 2021 to over $400 million by January 2022. Despite the exponential growth and the …
Technology / Feb. 5, 2022
Angel investors vs. venture capitalists
Angel investors and venture capitalists are two types of private investors who provide funding for early-stage and growth-stage companies. However, there are some key differences between them that we will cover in this article. Who are angel investors? High-net-worth individuals who invest in companies at an early stage in exchange for equity in the business are known as angel investors. They frequently invest their own funds and take a more active approach to investment, offering advice and mentoring to the businesses they support. The well-known angel investors in the crypto world include: Roger Ver — He is known as “Bitcoin …
Adoption / Feb. 15, 2023