NBA digital collectible contract has a serious security vulnerability, and the allowlist verification mechanism has defects.

robot
Abstract generation in progress

The NBA recently launched a series of digital collectibles, but after in-depth analysis, we found that there are significant security vulnerabilities in their sales contracts. This flaw allows malicious users to mint collectibles at no cost and gain improper benefits through sales.

The root of the problem lies in the flaws of the whitelist user signature verification mechanism. The contract failed to ensure the exclusivity and one-time use of whitelist signatures, which allowed attackers to reuse the signatures of other whitelist users to mint collectibles.

It is clear from the contract code that the verification function does not include the address of the transaction initiator in the signature content. At the same time, there is a lack of mechanisms to prevent the reuse of signatures. These basic security measures should be common knowledge in software development.

Surprisingly, such an obvious loophole appeared in a highly regarded project. This not only exposes the project's negligence in security audits but also highlights the challenges that blockchain projects face regarding code security.

This event reminds us once again that even large-scale and well-known projects may have fundamental security vulnerabilities. For blockchain projects, code security audits and ongoing vulnerability detection are particularly important. At the same time, this also serves as a wake-up call for the entire industry, urging all parties to pay more attention to the security construction of smart contracts.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 6
  • Repost
  • Share
Comment
0/400
GasFeeThundervip
· 14h ago
Another April 12th pitfall replica. Data in hand but still slacking off.
View OriginalReply0
ChainDetectivevip
· 20h ago
Tsk, this newbie-level bug can also go live.
View OriginalReply0
WhaleSurfervip
· 20h ago
Those who can't develop still dare to take this NBA order.
View OriginalReply0
RugPullAlarmvip
· 20h ago
Just use suckers for practice, not even basic audits were done.
View OriginalReply0
BlockchainGrillervip
· 20h ago
Watch the show closely, others are being played for suckers by suckers.
View OriginalReply0
OnchainHolmesvip
· 20h ago
It turns out the Allowlist can be copied and pasted, anyone with hands can play people for suckers.
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)