A flaw in an open-source library common across the Web3 space is affecting the security of pre-built smart contracts, affecting many NFT collections, including Coinbase.
See also: Porsche ends its new NFT program – phishing sites appear

The revelation came earlier from Web3 development platform Thirdweb . The announcement provided few details, which annoyed some users who wanted clarification that could help them protect their contracts.
Thirdweb said it became aware of the security issue on November 20 and implemented a fix two days later, but did not disclose the name of the library and the type or severity of the vulnerability to deter attackers.
The company says it has contacted the owners of the vulnerable library affecting multiple NFT collections and has also informed other protocols and organizations about the issue, sharing findings and workarounds.
The following smart contracts are affected by the flaw:
- AirdropERC20 (v1.0.3 and later), ERC721 (v1.0.4 and later), ERC1155 (v1.0.4 and later) ERC20Claimable, ERC721Claimable, ERC1155Claimable
- BurnToClaimDropERC721 (all versions)
- DropERC20, ERC721, ERC1155 (all versions)
- Loyalty Card
- MarketplaceV3 (All versions)
- Multiwrap, Multiwrap_OSRoyaltyFilter
- OpenEditionERC721 (v1.0.0 and later)
- Pack and Pack_OSRoyaltyFilter
- TieredDrop (all versions)
- TokenERC20, ECRC721, ERC1155 (all versions)
- SignatureDrop, SignatureDrop_OSRoyaltyFilter
- Split (low impact)
- TokenStake, NFTStake, EditionStake (All versions)
See also: Spotify is testing playlists that will be unlocked by NFT owners
“If you used our Solidity SDK to extend our base contract or build a custom contract, we do not believe the vulnerability is propagated to your contract,” Thirdweb explains, adding that this is not a guarantee because they cannot audit individual contracts.

Thirdweb shared the details of the exploit with the maintainers of the affected library and reported that it has not seen the vulnerability used in attacks.
The lack of details led some users to ask for clarification or to assume that the problem lies in Thirdweb's implementation of the library.
One user complained about the lack of transparency, asking for the CVE (Common Vulnerabilities and Exposures) identifier of the vulnerability and an explanation of how the workaround works.
Thirdweb says contract owners should immediately take remediation measures for all pre-built contracts created before November 22, 2023, at 7 p.m. PT. It is recommended to lock down vulnerable contracts, take a snapshot, and then transfer it to a new contract created with a non-vulnerable version of the library. here .
See also: Google Play: Changes policy for blockchain-based apps
What are NFTs?
NFTs are digital assets that use blockchain to enable exclusive ownership and exchange. Each NFT is unique and differentiated from the rest, making its owner's object special. This is achieved through smart contract technology, which allows for the automatic execution of agreed-upon terms and conditions for the exchange and transfer of NFTs.
NFTs operate on technology , where each NFT is recorded and stored on a decentralized distributed ledger. This ensures the integrity and non-alteration of data, making NFTs secure and reliable.
NFTs can be represented in a variety of formats, including images, videos, music, and even virtual items in games. Every time an NFT is bought or sold, the transaction is recorded on the blockchain, providing transparency and a history of the transactions. NFTs have emerged as a way for artists, creators, and fans to leverage their digital art and creative works. Artists can create and sell their own NFTs, allowing them to transact directly with their fans, without the need for intermediaries.
Source: bleepingcomputer
