PREMINT | NFT Hack

REPORTED LOSS $375K
Low Access Control ethereum

What happened

Users of the PREMINT NFT platform transferred approval rights to the hacker instead of logging into the platform due to a malicious code, uploaded by the hacker. $375k worth of NFT's were stolen by the hacker.

PREMINT is an NFT service intended to help project creators build access lists for new NFT projects based on various qualifications.

The PREMINT's platform website was attacked by a hacker utilizing a malicious JavaScript code.

When users tried to log into the platform, they instead signed over all approvals of their wallet to the attacker. The attacker proceeded to exploit affected wallets and send NFTs out of famous collections such as Murakami.Flowers, Kaiju Kingz and Azuki to a variety of his own wallets. Below a number of transaction made by the attacker:

https://etherscan.io/tx/0xc705b6ad…ab0662

https://etherscan.io/tx/0x81d49fc3…ba25a8

https://etherscan.io/tx/0x78607d70…ffb4ab

A majority of the funds were aggregated in this wallet (https://etherscan.io/address/0x99aeb028…826bf4). As the time of this writing 284 $ETH have been laundered through Tornado.Cash.

Attackers addresses:

https://etherscan.io/address/0xaab00f61…f281f3

https://etherscan.io/txs?a=0x4499bac5…aafeef

https://etherscan.io/address/0x4ed07767…d06ca1

https://etherscan.io/address/0x28733543…2bb49d

https://etherscan.io/address/0x0C979780…7418d0

https://etherscan.io/address/0x99aeb028…826bf4

Case & protocol details

Classification NFT / Frontend & Infrastructure
Protocol Type Exploit/Access control
Official Website www.premint.xyz/
Protocol Twitter/X @PREMINT_NFT

Evidence & learning

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.