Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesCopyBotsEarn
Thirdweb: There is a security vulnerability in a commonly used open source library. Contracts created on the platform before November 23 need to take

Thirdweb: There is a security vulnerability in a commonly used open source library. Contracts created on the platform before November 23 need to take

CointimeCointime2023/12/05 02:30
By:Cointime

Thirdweb, a Web3 developer platform, posted on X platform that they discovered a security vulnerability in commonly used open source libraries in the Web3 industry at 10:00 on November 21st Beijing time. This will affect various smart contracts in the Web3 ecosystem, including some pre-built smart contracts by Thirdweb. According to investigations so far, this vulnerability has not been exploited in ThirdWeb smart contracts. However, smart contract owners must take mitigating measures for certain pre-built contracts created on ThirdWeb before 11:00 on November 23rd Beijing time. Affected pre-built contracts include but are not limited to DropERC20, ERC721, ERC1155 (all versions), and AirdropERC20.

Thirdweb stated that the top priority is to protect affected customers from this vulnerability. If contract builders deployed one of these pre-built smart contracts using Thirdweb's dashboard or SDK before 11:00 on November 23rd Beijing time, they need to take some steps to mitigate potential exploitation of this vulnerability. In most cases, mitigation measures will involve locking the contract, taking a snapshot, and migrating to a new contract without known vulnerabilities.

It should be noted that if the contract builder's holder has locked tokens in any liquidity or staking pool, they should withdraw these tokens before starting these steps. Otherwise, the contract builder will not be able to distribute new tokens to these users. In addition, contract builders should use http://revoke.cash to request that their users revoke approval for all ThirdWeb contracts. The team has successfully launched remedial measures for all affected pre-built contracts created for Thirdweb after 11:00 on November 23rd Beijing time. All other ThirdWeb services, including wallets, payments, and infrastructure services, are not affected and operate as usual.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!

You may also like

Why Altcoins Can’t Make the Expected Mega Bullish Move? Analyst Reveals the Main Reason

While Bitcoin is trading near all-time highs, why are many altcoins nowhere near record highs?

Bitcoinsistemi2025/02/21 20:00

Spot Litecoin ETF Under SEC Review Added to DTCC List – What Does It Mean?

Canary's spot Litecoin ETF has been included in the DTCC's ETF list.

Bitcoinsistemi2025/02/21 20:00

This Project Focusing on Real World Assets (RWAs) Launches a New Program in Collaboration with Google Cloud! Here Are the Details

MANTRA, a Layer 1 blockchain designed for tokenized real-world assets (RWAs), has launched RWAccelerator.

Bitcoinsistemi2025/02/21 20:00

Investment Giant JPMorgan Analysts Announced a Slowdown in Cryptocurrency Demand! Here's Why

The cryptocurrency market is facing weakening demand as institutional investors reduce their interest in BTC and ETH futures.

Bitcoinsistemi2025/02/21 20:00