Cointime

Download App
iOS & Android

How to Secure NFTs: Part One

Validated Project

Non-fungible tokens are one of the newest and most popular applications of Web3 technology. Over the last couple of years, numerous collections have sold out within minutes and some of the most famous – like CryptoPunks and Bored Apes – traded hands for millions of dollars. NFTs are digital tokens that exist on a blockchain with an identifier that makes them immutable and unique at the same time. This relatively simple concept allows for various implementations that have the potential to impact various industries. While many people associate NFTs with their use as collectible JPEGs, there have been significant efforts to expand their usage to other areas.

The fact that each NFT is unique and cannot be deleted or modified enables a wide range of applications, some of which may not be immediately intuitive.

The key benefit of NFTs is right there in their name: non-fungible. This is another way to say unique, or unable to be reproduced. Since all the information related to an NFT is stored on a blockchain, this information can be publicly accessed and immediately verified. These exact properties are invaluable when applied to use cases such as certificates and ticketing, which help to eliminate counterfeits since the origin and exact original copy can be traced.

Another interesting application is the use of NFTs as “soul tokens” which represent the digital identity of a person. Since every person is completely unique, the use of a non-transferable NFT can be used as a Web3 digital identifier, almost like a digital passport.

The fact that NFTs are often minted as a part of a collection also finds application in fractional real estate investments, which allows users to invest in fractional shares of real estate without having to purchase the entire asset. Collectively, these shares represent the entire stake in a piece of property, like a Real Estate Investment Trust (REIT).

Even with all their promise and potential, it is still important that the community and projects be aware of the risks that are associated with working with NFTs.

NFT Hacks and Scams

With the growth of the NFT market, the sector is becoming an increasingly attractive target for hackers and bad actors. We’ve seen a number of examples of well-known celebrities shilling disreputable projects, while scammers are working hard to apply social engineering techniques to compromise the users’ private keys.

Phishing

Phishing is a type of attack that tricks a person into revealing sensitive information via fraudulent messages. Attackers send fraudulent messages to target users trying to get the private key or cheat them into signing a malicious transaction, thus stealing their funds. Those attacks are more related to secure operations and preventable with good security awareness. Platforms ranging from Twitter, Telegram, Reddit, and Discord all have active communities related to NFTs. Phishing has become one of the most common ways scammers get their hands on NFTs. Phishing occurs when a malicious attacker sets up a lure in the form of a fake website or contract to collect valuable user data or steal user funds. These phishing attacks often target users who are new to the space and aren’t fully aware of the various attack vectors.

On December 21, 2021, the Discord group of Monkey Kingdom was hacked and users reported that their wallets had been drained. Around $1.3 million worth of SOL was lost in the attack. Upon investigation, it appears that the official admin account was compromised and deployed bots into the Discord channels that sent bogus links to users claiming to grant user access to a limited edition mint. Unsuspecting users connected their wallets to get access to the free mint but instead had their wallets drained.

On June 5, 2022, the famous project Bored Apes Yacht Club, also referred to as BAYC, announced a hack resulting in the loss of around $350,000 worth of NFTs. The community manager’s account was hacked and the attacker posted fake links to a mint on the official BAYC and related project Otherside’s Discord channels. Yoshi Labs, the team behind the project, took swift action and made a patch to resolve the issue.

As with many things on the internet, great caution must be taken when clicking on unknown links in various social media channels. Users should exercise caution and conduct proper due diligence before clicking on links that offer so-called limited edition mints or rare NFTs. It is important to review the information and access that a user is providing in order to claim the offer. If the offer requires the user signs off on unknown transactions or to provide access to sensitive account functions, these may be considered red flags. It may be prudent to check with various trusted parties to make sure an opportunity is legitimate.

Rugpulls and Exit Scams

Rugpulls, also called exit scams, are exploits where the owners create new NFT projects with no intention of delivering on the promises they make. Instead, they wait until the project has attracted enough liquidity for them to dump their holdings on the market and walk away. When the exploits occur at the level of the project’s team, it might sometimes be more difficult to discern the authenticity of the project due to a lack of information, especially with new projects. It is important for potential investors to thoroughly review the project and take a look at the project wallet transaction history to see if transactions seem legitimate. It can also help to speak to other members of the community on various social media channels to try to identify the authenticity of the project. CertiK’s KYC process can help protect influencers and users from associating with high-risk NFT projects.

Private Key Hacks

As with cryptocurrencies, NFTs are held in a wallet which is secured and managed by a private key. Losing control of one’s private keys will result in the potential loss of all the assets the wallet contains, including NFTs. Your assets are only as secure as your private key is.

In an unfortunate case of “not your keys, not your crypto”, the NFT exchange Nifty Gateway was hacked in March 2021. The hackers stole user passwords and gained access to their accounts. An analysis showed that none of the affected users had two-factor authentication activated.

Holding NFTs and other crypto assets in cold storage provides the best user protection, since hot wallets that are constantly connected to the internet will always have a risk of being exploited. If hot wallets need to be used, be sure to have some sort of multi-factor authentication activated for better security.

Smart Contract Exploits

There is also the security of the smart contracts to consider. The security of the smart contract relies on its implementation and necessary validations/restrictions included in the code. Therefore, the correctness of the smart contract implementation directly affects the safety of the project.

When there are any vulnerabilities in the smart contract code, hackers will be able to exploit them and profit at the expense of the project and its users. Audits can help in this area to review the code and its implementation to ensure that security measures are sufficient to safeguard the funds and ensure the viability of the project.

The first version of CryptoPunks – one of the oldest and most valuable NFT collections – was hacked early in 2017. The vulnerability allowed NFTs to be sold without the user having to make any payment for the purchase of the NFT. The code was written in a way that prevented the seller from withdrawing the proceeds from the sale of an NFT. Instead, it was the buyer who would be able to withdraw these funds. This meant that a buyer could purchase an NFT and then subsequently withdraw the funds sent to the contract for the purchase of the NFT, therefore essentially minting NFTs for free. To fix the issue, the creators of the project, LarvaLabs, relaunched the project with the fix implemented in a new set of NFT contracts.

Best practice for smart contract developers is to have a review system in place and test code to ensure that all bugs are found and resolved. Rigorous testing should be used to test all different scenarios and especially when various contracts are integrated together. In general, developers should make use of battle-tested libraries and frameworks to reduce the bugs that might result from having untested custom code implementations. Auditing is an essential step for all smart contract projects. Expert code review can pick up on errors missed by developers, while building trust with the project’s community.

Keep an eye out for Part Two of this short series on NFT security, which will go into detail on some of the most common smart contract risks.

https://www.certik.com/resources/blog/68pBiYQxDq6Dxnsn2pVNXF-how-to-secure-nfts-part-one

NFT
Comments

All Comments

Recommended for you

  • US Spot Bitcoin ETF Sees $101.79M Net Inflow Yesterday

    On August 8, according to Trader T's monitoring, US spot bitcoin ETFs saw a net inflow of $101.79 million yesterday.

  • US Official: Ukraine Agrees to Avoid Strikes on Non-Russian Tankers and Black Sea Oil Facilities

    On August 8, according to a US official, Ukraine has agreed not to target certain non-Russian tankers and Black Sea infrastructure vital to Kazakhstan's crude oil exports. This follows ship attacks last month that caused loading disruptions. The US official said Ukraine has set up contact points so commercial shipping companies can communicate information and ensure safe passage. The commitment was reached after meetings between senior US government leaders and Ukrainian leadership, marking a potentially significant step toward increasing regional oil shipments. Previously, activity in the region had cooled significantly due to several recent attacks near the Caspian Pipeline Consortium terminal in Russia's Novorossiysk. (Jin Shi)

  • U.S. July Nonfarm Payrolls Fall by 23,000, Missing Market Expectations

    On August 7, U.S. nonfarm payrolls decreased by 23,000 in July, compared with market expectations of an increase of 80,000, and the previous value was an increase of 57,000.

  • US May and June Nonfarm Payroll Additions Revised Down by 103,000 Combined

    On August 7, the US Bureau of Labor Statistics: May nonfarm payroll additions were revised down from 129,000 to 63,000; June nonfarm payroll additions were revised down from 57,000 to 20,000. After the revisions, the combined additions for May and June were 103,000 lower than previously reported.

  • U.S. Rate Futures Market Sees Lower Odds of Fed September Hike

    On August 7, the probability of a Fed rate hike in September as priced by U.S. interest rate futures declined.

  • New York Gold Futures Top $4,400 per Ounce

    New York gold futures topped $4,400 per ounce, up 2.36% on the day.

  • Japan Finance Minister: FX Market Affected by Moves Not Driven by Actual Demand

    Japanese Finance Minister Satsuki Katayama said she and U.S. Treasury Secretary Bessent agreed that the foreign exchange market has been affected by moves not driven by actual demand.

  • BTC Breaks Through $65,000

    Market data shows BTC has broken through $65,000, currently reported at $65,007.44, with a 24-hour increase of 0.6%. The market is highly volatile, please exercise risk control.

  • Brent Crude Drops 2.00% Intraday to $81.07/Barrel

    Brent crude oil fell 2.00% during the day, now at $81.07 per barrel. (Jin Shi)

  • Trump: Data Centers May Be More Important Than Oil

    August 7 news, U.S. President Trump said in an interview with Punchbowl News, "I saw the other day that Texas seems to be opposed to building data centers. I think that's a mistake. I'm not taking a position—I just think it's a mistake, because there are other communities that want to build data centers. When a community is willing to accept data centers, it means a lot of money will flow into that community. I don't think they're ugly. Some of the data centers I've seen are the most incredible buildings I've ever seen. They are very important to the economy. If Texas says no to data centers, that's a mistake, because data centers may be more important than oil."