SlowMist Says ERC721R Sample Contract Flaw is Essentially Due to Excessive Owner Privileges

Core Go Pocket developer Ben said a flaw in the ERC721R sample contract could be exploited by the project to perform RugPull. According to the preliminary analysis of the SlowMist security team, this flaw is essentially due to the problem of excessive owner permissions. In the ERC721R example contract, the owner can arbitrarily set the NFT address returned by the user via the setRefundAddress function.
Source

Security Incidents

NFT

Related News
Bybit hackers move over half the stolen ETH onto Bitcoin, largely using ThorChain Bybit hackers move over half the stolen ETH onto Bitcoin, largely using ThorChain
Stablecoin neobank Infini exploited for $49 million: security analysts Stablecoin neobank Infini exploited for $49 million: security analysts
Sony’s Soneium debuts its first music NFT collection with crypto record label Sony’s Soneium debuts its first music NFT collection with crypto record label
NoOnes CEO Ray Youssef discloses $8 million exploit weeks after the fact, confirming crypto sleuth ZachXBT's investigation NoOnes CEO Ray Youssef discloses $8 million exploit weeks after the fact, confirming crypto sleuth ZachXBT's investigation
Arbitrum, Azuki-backed Animecoin unveils tokenomics with over 50% community allocation Arbitrum, Azuki-backed Animecoin unveils tokenomics with over 50% community allocation
Latest News More More
3 Days Ago Argentine prosecutor seeks to freeze $110 million in proceeds tied to Libra memecoin scandal: report
3 Days Ago Mt. Gox moves over $1 billion worth of bitcoin to unmarked address: Arkham
4 Days Ago Ethereum devs activate Pectra upgrade on Sepolia testnet in last phase before mainnet rollout
4 Days Ago Binance Records $3.97B Weekly Inflows
4 Days Ago MEXC Partners With Hacken to Increase Security Standards
delate
Use TokenInsight App All Crypto Insights Are In Your Hands
Open