TreasureDAO Hack
What happened
The exploiter's address:
https://arbiscan.io/address/0x9b1acd43…d48e68
The example of the transaction:
https://arbiscan.io/tx/0x37222d3a…a89269
The protocol was exploited in several transactions, leading to more than 100 NFTs being stolen from different collections of Treasure Marketplace.
The exploiter:
- called buyItem() with valid NFT token and NFT ID, but with the invalid 0 quantity
- Treasure Marketplace sells the NFT but charges 0 MAGIC (due to 0 quantity)
The hack is made possible due to a bug in distinguishing ERC721 and ERC1155 in buyItem(), which miscalculates the price of ERC721 as ERC1155 with the given 0 quantity.
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report twitter.com
- report Report twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.