Nft Trader Hack

TOTAL LOST $3.0M
Medium Reentrancy ethereum

What happened

NFT Trader platform exploited via reentrancy attack, resulting in the loss of NFTs and 481,888 USD worth 210.8 ETH.

NFT Trader, a trading platform for NFTs, was exploited on Dec 16, 2023, through a reentrancy attack. The vulnerability was in the project's old smart contract, which had approvals of user funds. The attacker stole various NFTs, including Bored Ape Yacht Club, Mutant Ape Yacht Club, and World of Women.

The APE tokens were swapped for ETH and then deposited into TornadoCash. The attacker communicated with the project via on-chain messages, expressing their willingness to return the stolen NFTs, which were eventually returned to the project. The total loss amounted to 481,888 USD worth 210.8 ETH.

Attacker Addresses:

https://etherscan.io/address/0x909F2159…478fda

https://etherscan.io/address/0xd717b85b…43cdf0

Malicious Contract Address:

https://etherscan.io/address/0xc446e0a1…4d6ebb

Malicious Transactions:

https://etherscan.io/tx/0x18f21648…7d9c39

https://etherscan.io/tx/0x11bb6c85…13a3cc

Funds Draining Transactions:

https://etherscan.io/tx/0x3d79e70d…f0526d

https://etherscan.io/tx/0xf31333bd…71112a

TornadoCash Deposit Transaction:

https://etherscan.io/tx/0x7d64e9b4…a99222

On-chain Message from Attacker:

https://etherscan.io/tx/0xc2f91dba…8d9391

Case & protocol details

Classification NFT,Exchange (DEX) / Reentrancy
Protocol Type Exploit/Reentrancy
Smart Contract Language Solidity
Official Website www.nfttrader.io/
Protocol Twitter/X @NftTrader

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.