🎉 [Gate 30 Million Milestone] Share Your Gate Moment & Win Exclusive Gifts!
Gate has surpassed 30M users worldwide — not just a number, but a journey we've built together.
Remember the thrill of opening your first account, or the Gate merch that’s been part of your daily life?
📸 Join the #MyGateMoment# campaign!
Share your story on Gate Square, and embrace the next 30 million together!
✅ How to Participate:
1️⃣ Post a photo or video with Gate elements
2️⃣ Add #MyGateMoment# and share your story, wishes, or thoughts
3️⃣ Share your post on Twitter (X) — top 10 views will get extra rewards!
👉
The NBA digital collectible contract has a serious vulnerability, allowing attackers to profit at zero cost.
NBA Digital Collectible Contract Exposes Serious Vulnerability, Attackers Can Profit at No Cost
Recently, the NBA launched a digital collectibles project, but the smart contract of the project was found to have major security risks. Security researchers have pointed out that a vulnerability in the contract could be exploited by bad actors to mint and monetize collectibles at zero cost.
The root cause of this vulnerability is a flaw in the contract's verification mechanism for the signatures of whitelisted users. Specifically, the contract fails to ensure the exclusivity and one-time use of whitelist signatures. This means that an attacker can reuse the signatures of other whitelisted users to mint collectibles.
From the leaked contract code, it can be seen that the verify function does not include the address of the transaction sender in the signature content when verifying the signature. In addition, the contract does not have mechanisms in place to prevent the signature from being used multiple times. These security measures should be basic common knowledge in smart contract development.
!
Industry experts expressed shock at the fact that such a basic security vulnerability appeared in such a well-known project, which is truly hard to believe. This incident once again highlights that even the most basic security practices cannot be ignored in the development of blockchain projects.
This incident has also sounded the alarm for other blockchain projects. It reminds developers to be especially cautious when designing smart contracts, particularly regarding the security of key aspects such as signature verification and permission control. At the same time, it highlights the importance of conducting comprehensive security audits before a project goes live.
With the rapid development of the digital collectibles market, similar security issues are likely to increase. Therefore, both project parties and users need to enhance their security awareness and take necessary preventive measures. For investors, understanding the security status of any digital collectibles project before participating has become increasingly important.
!