Latest

Certik: Vulnerability of Ember Sword NFT auction contract led to losses of $195,000

Cryptosecurity experts at Certik recently uncovered a vulnerability in the Ember Sword NFT auction contract, resulting in losses of $195,000 for 159 users.

The vulnerability impacted users who had approved the Ember Sword NFT contract, enabling attackers to receive approximately 60 WETH. Certik has recommended that users withdraw their approval of the relevant contract on the Polygon blockchain as soon as possible.

The vulnerability in the Ember Sword NFT contract allowed scammers to manipulate rates and withdraw funds from service clients. According to Certik, this vulnerability appears to be caused by a bug in the Ember Sword NFT auction contract’s code.

Scammers took advantage of this vulnerability by placing fraudulent bets that would cover real user bets, allowing them to win auctions at a reduced price. Subsequently, they would sell the NFT at a higher price, profiting from the price difference.

Certik had previously reported a significant increase in financial losses among digital asset holders due to the compromise of private crypto keys.