Flooring Protocol Hack

Reported loss $1.6M
Ethereum
Arbitrary External Call

What happened

On December 17, 2023 (UTC), an attacker used a flaw in Flooring Protocol, an NFT liquidity protocol on Ethereum, to take 36 Pudgy Penguins and 15 Bored Apes from users who had approved the protocol to move their NFTs. The haul was worth about 690 ETH (roughly $1.54 million), and the attacker sold the NFTs on Blur for about $1.5 to $1.6 million.

Flooring said the bug was in its peripheral/multicall contract, deployed a fix within about two hours, and said assets held in its vaults and safeboxes were not affected. The researcher foobar flagged the thefts on-chain and linked them to a contract upgrade made several days earlier; Protos noted that Flooring's published audits predated that upgrade. Boring Security warned that victims might not get their NFTs back because the attacker had already sold them.

How it happened

  1. Users had granted the Flooring contract (proxy 0x49AD262C49C7aA708Cc2DF262eD53B64A17Dd5EE) operator approval over their NFT collections.
  2. A recent upgrade exposed extMulticall, which forwarded caller-supplied (target, callData) pairs to any contract with Flooring as msg.sender, without restricting targets or checking who owned the assets.
  3. The attacker, from 0x4d0d746e0f66bf825418e6b3def1a46ec3c0b847 through contract 0x7e5433f02f4bf07c4f2a2d341c450e07d7531428, built calls of safeTransferFrom(victim, attacker, tokenId) on the NFT contracts and passed them to extMulticall.
  4. Because the NFT contracts saw an approved operator, they moved the tokens. One transaction alone took 36 Pudgy Penguins from a single wallet.
  5. The attacker sold the stolen Bored Apes and Pudgy Penguins on Blur.

Protocol details

Classification Access Control
Protocol Type NFT Marketplace
Implementation language Solidity
Protocol links @floorprotocol

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.