Ethscriptions Hack

Reported loss $3K
Ethereum
Improper Access Control

What happened

In July 2023, an attacker took about 202 ethscriptions from about 123 addresses through a bug in the Ethscriptions.com marketplace contract. The contract went live on July 12 and was exploited within hours. Ethscriptions are Ethereum assets written into transaction calldata and tracked by off-chain indexers, so a smart contract cannot check who owns one. The marketplace recorded a deposit for anyone who called its deposit function for an ethscription ID, even if the caller had never sent that ethscription. An attacker could register a fake deposit for an ethscription another user had really deposited, then withdraw it.

Creator Tom Lehman said the bug was in this one contract (0x3ca843b98a2fe8ef69bb0f169afad3812c275f5e), not in the Ethscriptions protocol. He paused the marketplace and said it would relaunch only after a protocol extension let contracts transfer an ethscription only back to the address that deposited it. He said the stolen ethscriptions would not be reversed, because the protocol's rules had worked as designed. Decrypt reported that the total value lost was unclear; some ethscriptions had sold for up to 5 ETH.

How it happened

  1. A legitimate user A sent ethscription X to the marketplace contract. Under the protocol, the marketplace now owned X, and the contract set storedEthscriptions[A][X] = true.
  2. The attacker B called the marketplace's deposit function for the same ID X. The protocol ignored this, because B did not own X. The contract had no way to check ownership, so it also set storedEthscriptions[B][X] = true.
  3. B then requested a withdrawal of X. The contract checked only storedEthscriptions[B][X], which was true, and emitted a transfer of X to B.
  4. Because the marketplace really held X from A's deposit, the protocol treated the transfer as valid, and B received A's ethscription.

Protocol details

Classification Access Control
Protocol Type NFTfi
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.