Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

Thirdweb Tackles Security Flaw in Web3 Library Impacting its Smart Contracts

Altszn.com by Altszn.com
December 5, 2023
in Metaverse, Web3
0
Thirdweb Tackles Security Flaw in Web3 Library Impacting its Smart Contracts
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter


by Nik Asti

Published: December 05, 2023 at 2:30 am Updated: December 05, 2023 at 2:31 am

by Victor Dey

Edited and fact-checked:
December 05, 2023 at 2:30 am

To improve your local-language experience, sometimes we employ an auto-translation plugin. Please note auto-translation may not be accurate, so read original article for precise information.

In Brief

Thirdweb discovered a significant security vulnerability in a common open-source library widely used in the web3 industry for smart contracts.

Thirdweb Addresses Security Flaw in Web3 Library Affecting Smart Contracts

Web3 development platform Thirdweb recently became aware of a critical security vulnerability in a widely used open-source library on November 20th, 2023. The discovery has significant implications for numerous smart contracts within the web3 ecosystem, including some of Thirdweb’s own pre-built contracts.

The vulnerability affects various pre-built contracts like DropERC20, ERC721, ERC1155 and AirdropERC20. While Thirdweb’s investigation so far indicates no exploitation in their contracts, they have issued an urgent call to action for smart contract owners.

Smart contract owners who used Thirdweb’s dashboard or SDKs to deploy contracts before November 22nd, 2023, are advised to follow specific mitigation steps to prevent potential exploitation. These steps, which vary based on the contract’s nature, generally involve locking the contract, taking a snapshot, and migrating to a new contract.

IMPORTANT

On November 20th, 2023 6pm PST, we became aware of a security vulnerability in a commonly used open-source library in the web3 industry.

This impacts a variety of smart contracts across the web3 ecosystem, including some of thirdweb’s pre-built smart contracts.…

— thirdweb (@thirdweb) December 5, 2023

Guidance for Thirdweb Smart Contract Owners

Thirdweb and its security partners have developed a tool to assist contract owners in determining and performing necessary mitigation steps. This tool, along with a detailed guide, is available on Thirdweb’s blog.

Upon learning of the vulnerability, Thirdweb’s security team, in collaboration with audit partners, investigated the issue and implemented a fix for all impacted contracts created after November 22nd, 2023. Contracts deployed after this date using the latest version do not suffer from this vulnerability.

In response to this incident, Thirdweb is increasing its investment in security measures.

This includes doubling bug bounty payouts and implementing stricter auditing processes. Thirdweb pledged to cover the gas fees for contract mitigations. Additionally, the platform has advised users to revoke approvals on Thirdweb contracts as a precautionary measure.

Looking forward, Thirdweb aims to enhance security protocols and create a robust environment for web3 developers. the platform have also reached out to the maintainers of the affected library and other potentially impacted teams to share their findings and mitigation strategies.

This incident underscores the importance of vigilant security measures in the rapidly evolving web3 landscape. Thirdweb’s proactive approach and transparent communication aim to ensure the safety and resilience of the web3 community.

Disclaimer

In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, we suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice.

About The Author

Nik is an accomplished analyst and writer at Metaverse Post, specializing in delivering cutting-edge insights into the fast-paced world of technology, with a particular emphasis on AI/ML, XR, VR, on-chain analytics, and blockchain development. His articles engage and inform a diverse audience, helping them stay ahead of the technological curve. Possessing a Master’s degree in Economics and Management, Nik has a solid grasp of the nuances of the business world and its intersection with emergent technologies.

More articles

Nik Asti



Nik is an accomplished analyst and writer at Metaverse Post, specializing in delivering cutting-edge insights into the fast-paced world of technology, with a particular emphasis on AI/ML, XR, VR, on-chain analytics, and blockchain development. His articles engage and inform a diverse audience, helping them stay ahead of the technological curve. Possessing a Master’s degree in Economics and Management, Nik has a solid grasp of the nuances of the business world and its intersection with emergent technologies.



More articles





Read More: mpost.io

Tags: ContractsflawimpactingLibraryMetaverseSecuritySmartTacklesThirdwebWeb3
ADVERTISEMENT

Recent

NFT founder stole millions from Bitcoin project, investors allege

NFT founder stole millions from Bitcoin project, investors allege

May 15, 2025
Danger signs for Bitcoin as retail abandons it to institutions: Sky Wee

Danger signs for Bitcoin as retail abandons it to institutions: Sky Wee

May 14, 2025
Crypto VC deals drop in Q1, but funding more than doubles: PitchBook

Crypto VC deals drop in Q1, but funding more than doubles: PitchBook

May 14, 2025

Categories

  • Bitcoin (4,858)
  • Blockchain (11,412)
  • Crypto (9,352)
  • Dark Web (549)
  • DeFi (8,397)
  • Ethereum (4,905)
  • Metaverse (7,530)
  • Monero (290)
  • NFT (1,481)
  • Solana (5,047)
  • Web3 (20,704)
  • Zcash (509)

Category

Select Category

    Advertise

    Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

    Useful Links

    Advertise
    DMCA
    Contact Us
    Privacy Policy
    Shipping & Returns
    Terms of Use

    Resources

    Exchanges
    Changelly
    Web3 Jobs

    Recent News

    NFT founder stole millions from Bitcoin project, investors allege

    NFT founder stole millions from Bitcoin project, investors allege

    May 15, 2025
    Danger signs for Bitcoin as retail abandons it to institutions: Sky Wee

    Danger signs for Bitcoin as retail abandons it to institutions: Sky Wee

    May 14, 2025

    © 2022 Altszn.com. All Rights Reserved.

    No Result
    View All Result
    • Home
      • Home – Layout 1
      • Home – Layout 2
      • Home – Layout 3

    © Altszn.com. All Rights Reserved.

    • bitcoinBitcoin (BTC) $ 102,009.00
    • ethereumEthereum (ETH) $ 2,540.15
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.48
    • bnbBNB (BNB) $ 646.29
    • solanaSolana (SOL) $ 171.25
    • usd-coinUSDC (USDC) $ 0.999929
    • dogecoinDogecoin (DOGE) $ 0.225435
    • cardanoCardano (ADA) $ 0.773322
    • tronTRON (TRX) $ 0.269652
    • staked-etherLido Staked Ether (STETH) $ 2,539.48
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 101,864.00
    • suiSui (SUI) $ 3.74
    • chainlinkChainlink (LINK) $ 16.29
    • wrapped-stethWrapped stETH (WSTETH) $ 3,055.52
    • avalanche-2Avalanche (AVAX) $ 23.77
    • stellarStellar (XLM) $ 0.297118
    • shiba-inuShiba Inu (SHIB) $ 0.000015
    • hedera-hashgraphHedera (HBAR) $ 0.199118
    • leo-tokenLEO Token (LEO) $ 8.87
    • hyperliquidHyperliquid (HYPE) $ 24.51
    • the-open-networkToncoin (TON) $ 3.15
    • bitcoin-cashBitcoin Cash (BCH) $ 391.69
    • litecoinLitecoin (LTC) $ 96.46
    • polkadotPolkadot (DOT) $ 4.79
    • usdsUSDS (USDS) $ 0.999978
    • wethWETH (WETH) $ 2,541.63
    • moneroMonero (XMR) $ 343.54
    • pi-networkPi Network (PI) $ 0.863322
    • wrapped-eethWrapped eETH (WEETH) $ 2,711.27
    • pepePepe (PEPE) $ 0.000013
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999717
    • bitget-tokenBitget Token (BGB) $ 4.66
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 102,073.00
    • whitebitWhiteBIT Coin (WBT) $ 30.19
    • uniswapUniswap (UNI) $ 6.40
    • bittensorBittensor (TAO) $ 425.30
    • daiDai (DAI) $ 1.00
    • nearNEAR Protocol (NEAR) $ 2.88
    • aptosAptos (APT) $ 5.53
    • aaveAave (AAVE) $ 224.53
    • okbOKB (OKB) $ 53.63
    • ondo-financeOndo (ONDO) $ 0.971040
    • jito-staked-solJito Staked SOL (JITOSOL) $ 205.77
    • kaspaKaspa (KAS) $ 0.114876
    • ethereum-classicEthereum Classic (ETC) $ 19.14
    • internet-computerInternet Computer (ICP) $ 5.44
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • tokenize-xchangeTokenize Xchange (TKX) $ 36.09
    • bitcoinBitcoin (BTC) $ 102,009.00
    • ethereumEthereum (ETH) $ 2,540.15
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.48
    • bnbBNB (BNB) $ 646.29
    • solanaSolana (SOL) $ 171.25
    • usd-coinUSDC (USDC) $ 0.999929
    • dogecoinDogecoin (DOGE) $ 0.225435
    • cardanoCardano (ADA) $ 0.773322
    • tronTRON (TRX) $ 0.269652
    • staked-etherLido Staked Ether (STETH) $ 2,539.48
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 101,864.00
    • suiSui (SUI) $ 3.74
    • chainlinkChainlink (LINK) $ 16.29
    • wrapped-stethWrapped stETH (WSTETH) $ 3,055.52
    • avalanche-2Avalanche (AVAX) $ 23.77
    • stellarStellar (XLM) $ 0.297118
    • shiba-inuShiba Inu (SHIB) $ 0.000015
    • hedera-hashgraphHedera (HBAR) $ 0.199118
    • leo-tokenLEO Token (LEO) $ 8.87
    • hyperliquidHyperliquid (HYPE) $ 24.51
    • the-open-networkToncoin (TON) $ 3.15
    • bitcoin-cashBitcoin Cash (BCH) $ 391.69
    • litecoinLitecoin (LTC) $ 96.46
    • polkadotPolkadot (DOT) $ 4.79
    • usdsUSDS (USDS) $ 0.999978
    • wethWETH (WETH) $ 2,541.63
    • moneroMonero (XMR) $ 343.54
    • pi-networkPi Network (PI) $ 0.863322
    • wrapped-eethWrapped eETH (WEETH) $ 2,711.27
    • pepePepe (PEPE) $ 0.000013
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999717
    • bitget-tokenBitget Token (BGB) $ 4.66
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 102,073.00
    • whitebitWhiteBIT Coin (WBT) $ 30.19
    • uniswapUniswap (UNI) $ 6.40
    • bittensorBittensor (TAO) $ 425.30
    • daiDai (DAI) $ 1.00
    • nearNEAR Protocol (NEAR) $ 2.88
    • aptosAptos (APT) $ 5.53
    • aaveAave (AAVE) $ 224.53
    • okbOKB (OKB) $ 53.63
    • ondo-financeOndo (ONDO) $ 0.971040
    • jito-staked-solJito Staked SOL (JITOSOL) $ 205.77
    • kaspaKaspa (KAS) $ 0.114876
    • ethereum-classicEthereum Classic (ETC) $ 19.14
    • internet-computerInternet Computer (ICP) $ 5.44
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • tokenize-xchangeTokenize Xchange (TKX) $ 36.09