ERC-2771 integration introduces address spoofing vulnerability — OpenZeppelin

The smart contract vulnerability arises after the integration of ERC-2771 and Multicall standards. OpenZepplin identified 13 sets of vulnerable smart contracts.

Soon after Thirdweb revealed a security vulnerability that could impact a variety of common smart contracts used across the Web3 ecosystem, OpenZeppelin identified two specific standards as the root cause of the threat.

On Dec. 4, Thirdweb reported a vulnerability in a commonly used open-source library, which could impact pre-built contracts, including DropERC20, ERC721, ERC1155 (all versions), and AirdropERC20.

James Edwards, the lead maintainer for cybersecurity investigator Librehash, said that while AI chatbots have the ability to develop smart contracts, deploying them in a live environment is risky.

Read more

bitcoin
Bitcoin (BTC) $ 91,400.49
ethereum
Ethereum (ETH) $ 3,032.23
tether
Tether (USDT) $ 1.00
bnb
BNB (BNB) $ 894.78
xrp
XRP (XRP) $ 2.20
solana
Wrapped SOL (SOL) $ 138.35
dogecoin
Dogecoin (DOGE) $ 0.14983
chainlink
Chainlink (LINK) $ 13.33
shiba-inu
Shiba Inu (SHIB) $ 0.000008
nexo
NEXO (NEXO) $ 0.951879
enjincoin
Enjin Coin (ENJ) $ 0.03217
cardano
Cardano (ADA) $ 0.424205