Nft Trader Hack
Incident Overview
NFT Trader platform exploited via reentrancy attack, resulting in the loss of NFTs and 481,888 USD worth 210.8 ETH.
NFT Trader, a trading platform for NFTs, was exploited on Dec 16, 2023, through a reentrancy attack. The vulnerability was in the project's old smart contract, which had approvals of user funds. The attacker stole various NFTs, including Bored Ape Yacht Club, Mutant Ape Yacht Club, and World of Women.
The APE tokens were swapped for ETH and then deposited into TornadoCash. The attacker communicated with the project via on-chain messages, expressing their willingness to return the stolen NFTs, which were eventually returned to the project. The total loss amounted to 481,888 USD worth 210.8 ETH.
Attacker Addresses:
https://etherscan.io/address/0x909F2159…478fda
https://etherscan.io/address/0xd717b85b…43cdf0
Malicious Contract Address:
https://etherscan.io/address/0xc446e0a1…4d6ebb
Malicious Transactions:
https://etherscan.io/tx/0x18f21648…7d9c39
https://etherscan.io/tx/0x11bb6c85…13a3cc
Funds Draining Transactions:
https://etherscan.io/tx/0x3d79e70d…f0526d
https://etherscan.io/tx/0xf31333bd…71112a
TornadoCash Deposit Transaction:
https://etherscan.io/tx/0x7d64e9b4…a99222
On-chain Message from Attacker:
https://etherscan.io/tx/0xc2f91dba…8d9391
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Nft Trader, these are the critical security checks that could have prevented this incident (December 2023).
- Verify all logic paths related to Reentrancy are guarded by proper access controls and input validation - see the Reentrancy attack class for patterns
- Check that all state-changing functions follow the Checks-Effects-Interactions (CEI) pattern to prevent reentrancy and logic ordering bugs
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialRelated Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
- 01
-
02
Web Archive https://archive.ph/wUm2p
Learn to Prevent the Next Nft Trader
The Nft Trader hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.