TheNFTV2 Hack

Reported loss $19K
Ethereum
Withdrawal Logic Flaw

What happened

On November 25, 2023 an attacker drained the TheDAO tokens held by TheNFT, an Ethereum NFT project in which each "TheDAO SEC Report" NFT wraps one TheDAO token. MetaTrust put the loss on the V2 contract at about $19,000. Burning an NFT pays out its TheDAO token and parks the NFT at a dead address, from where it is normally restored by paying the token back. The flaw was in how burn and transferFrom handled approvals. An approval granted before a burn survived it, so the attacker could pull the burned NFT back from the dead address for free and burn it again. The project said this was an unpatched variant of an approval bug found in January 2022, which V2 had been deployed to fix. Both V1 and V2 lost their TheDAO reserves, but NFT ownership records were not affected. In April 2024 the project deployed a new redeemer contract, seeded with 555 donated TheDAO tokens, to cover the shortfall.

Attack tx: 0xd5b4d68432cbbd912130bbb5b93399031ddbb400d8f723c78050574de7533106

How it happened

  1. The attacker moved NFT #1071 into an attack contract and took a Uniswap V2 flash swap of WETH from the TheDAO/WETH pair.
  2. Inside the callback, the contract approved itself for the NFT and called burn, receiving the TheDAO token backing it while the NFT went to the dead address 0x...74eda0.
  3. Because the approval was not cleared, it then called transferFrom to move the NFT from the dead address back to itself without paying to restore it.
  4. It repeated approve, burn and transfer until it held enough TheDAO to settle the flash swap, sent the TheDAO to the pair and kept the leftover WETH as ETH.

Protocol details

Classification Protocol Logic
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.