FlippazOne Hack

REPORTED LOSS $7K
Low Access Control

What happened

The creators of the FlippazOne project created a NFT smart contract, which is also an auction contract. The contract included a serious vulnerability in the ownerWithdrawAllTo() function, in which there is no verification of the owner, which allows anyone to take all the funds of the contract through calling this public function.

The contract creator of FlippazOne created a contract with a vulnerability that enables anyone to withdraw all $ETH from the contract to any address. The vulnerability lies in the fact that this function does not have a check on the owner, which means anyone can pick up $ETH tokens to their address at any time. This account with address (https://etherscan.io/address/0x194a39f4…ff0b14) made a bid sending 1.5 $ETH to the FlippazOne contract that were successfully withdrawn by unverified contract (https://etherscan.io/address/0xb314fd4a…9c82b6) in this transaction: https://etherscan.io/tx/0x670da209…031fa0.

Then another 4 $ETH were withdrawn by EOA address in this transaction: https://etherscan.io/tx/0xf2cc19d4…0a3762

As the time of this writing information on this case is scarce. More sources will be added if the case should develop.

Vulnerable contract address: https://etherscan.io/address/0xE85A08Cf…c3e944

Contract owner and creator: https://etherscan.io/address/0x7f377ee9…99d9d3

Case & protocol details

Classification NFT
Protocol Type Exploit/Access control
Affected asset / contract FlippazOne

Evidence & learning

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.