Recently, a well-known figure in the Blockchain security field, Slow Mist founder Yu Xian (online name Cos), released an important message on social media, attracting widespread attention from the crypto world. He pointed out that there is a serious security vulnerability in the smart contracts of the well-known NFT platform SuperRare, which could pose a potential risk to platform users.



According to the cosine analysis, a key judgment condition in the SuperRare smart contracts used an inappropriate logical operator. Specifically, the contract used '!=' (not equal) instead of '==' (equal) operator during ownership verification. This seemingly minor error could pose significant security risks.

The consequence of this vulnerability is that, aside from a specific contract owner (whose address happens to be 0xc2F39), any other user may have the opportunity to perform unauthorized operations. This means that malicious actors could exploit this vulnerability to cause unpredictable damage to the SuperRare platform.

Yuxian's discovery once again emphasizes the importance of code review and security testing in blockchain and smart contracts development. Even a small programming error can lead to serious security issues. This also reminds developers of NFT platforms and other blockchain projects to be extra cautious when deploying smart contracts, ensuring that every line of code undergoes rigorous review and testing.

As this news spreads, industry insiders and users are closely following the response and subsequent measures taken by the SuperRare team. This incident may also spark a broader discussion on how to enhance the security of smart contracts and better protect the safety of user assets.
COS-1.92%
RARE-1.53%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 7
  • Share
Comment
0/400
just_here_for_vibesvip
· 07-29 00:15
The contract is not clear, just send it directly.
View OriginalReply0
GamefiHarvestervip
· 07-28 13:52
One doesn't equal and both can be mistaken? That's out of the question.
View OriginalReply0
GateUser-b37efd0fvip
· 07-28 13:48
Bull Run 🐂
Reply0
GateUser-b37efd0fvip
· 07-28 13:48
Ape In 🚀
Reply0
GateUser-b37efd0fvip
· 07-28 13:46
Ape In 🚀
Reply0
GateUser-b37efd0fvip
· 07-28 13:45
Ape In 🚀
Reply0
FOMOSapienvip
· 07-28 13:42
This pot is super rare and needs to be carried.
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)