Bad Guys by RPF Hack
What happened
On September 2, 2022, the whitelist mint for Bad Guys by RPF, an NFT collection from the scam watchdog Rug Pull Finder, was exploited on Ethereum. The mint was meant to allow one NFT per wallet. But WhiteListMint accepted a caller-supplied chosenAmount and only checked that the caller had not minted before.
One whitelisted address, 0xBD8A137E79C90063cd5C0DB3Dbabd5CA2eC7e83e, minted 400 NFTs in a single transaction (0xb613c68b00c532fe9b28a50a91c021d61a98d907d0217ab9b44cd8d6ae441d9f). Bitcoinist reported that more than 450 NFTs were taken in total out of a planned 1,221. Bitcoinist reported that RPF agreed with the exploiters to get back about 366 of them for 2.5 ETH. RPF acknowledged the bug and said it had not used an independent auditor.
How it happened
- The attacker held a valid whitelist spot and so could produce a Merkle proof for
WhiteListMint. - The function's only per-wallet limit was
require(_numberMinted(msg.sender) < 1), which checks past mints, not the size of the current request. - The attacker called
WhiteListMint(proof, 400). Because they had never minted, the check passed. - The contract then called
_safeMint(msg.sender, chosenAmount), sending 400 NFTs to the attacker in one transaction.
Protocol details
Evidence
- analysis DeFiLlama defillama.com
- analysis Bad Guys NFT - Learn EVM Attacks (Coinspect) coinspect.com
- analysis DeFiHackLabs PoC BadGuysbyRPF_exp.sol raw.githubusercontent.com
- analysis Bad Actors Exploit NFT Watchdog After Collection Mint (Bitcoinist) bitcoinist.com
- analysis RugDoctorApe on X, 2022-09-02 (fxtwitter mirror of status 1565739119606890498) api.fxtwitter.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.