📢 Gate Square Exclusive: #WXTM Creative Contest# Is Now Live!
Celebrate CandyDrop Round 59 featuring MinoTari (WXTM) — compete for a 70,000 WXTM prize pool!
🎯 About MinoTari (WXTM)
Tari is a Rust-based blockchain protocol centered around digital assets.
It empowers creators to build new types of digital experiences and narratives.
With Tari, digitally scarce assets—like collectibles or in-game items—unlock new business opportunities for creators.
🎨 Event Period:
Aug 7, 2025, 09:00 – Aug 12, 2025, 16:00 (UTC)
📌 How to Participate:
Post original content on Gate Square related to WXTM or its
NBA digital collectible contract has a serious security vulnerability, and the allowlist verification mechanism has defects.
The NBA recently launched a series of digital collectibles, but after in-depth analysis, we found that there are significant security vulnerabilities in their sales contracts. This flaw allows malicious users to mint collectibles at no cost and gain improper benefits through sales.
The root of the problem lies in the flaws of the whitelist user signature verification mechanism. The contract failed to ensure the exclusivity and one-time use of whitelist signatures, which allowed attackers to reuse the signatures of other whitelist users to mint collectibles.
It is clear from the contract code that the verification function does not include the address of the transaction initiator in the signature content. At the same time, there is a lack of mechanisms to prevent the reuse of signatures. These basic security measures should be common knowledge in software development.
Surprisingly, such an obvious loophole appeared in a highly regarded project. This not only exposes the project's negligence in security audits but also highlights the challenges that blockchain projects face regarding code security.
This event reminds us once again that even large-scale and well-known projects may have fundamental security vulnerabilities. For blockchain projects, code security audits and ongoing vulnerability detection are particularly important. At the same time, this also serves as a wake-up call for the entire industry, urging all parties to pay more attention to the security construction of smart contracts.