Rug Pull Finder's NFT contract was abused to allow two scammers to mint 450 NFTs instead of one per wallet.
In an ironic twist, Rug Pull Finder (RPF), a nonfungible token (NFT) watchdog focused on identifying Web3-based fraud has fallen victim to a smart contract exploit of its own.
According to the NFT investigator’s post on Twitter on Sept. 2, two people exploited a technical flaw in the project during the free mint stage — pilfering 450 NFTs out of a possible 1,221 which were intended to be limited to one per wallet.
As discussed on our Twitter space's earlier today -
— Rug Pull Finder (@rugpullfinder) September 2, 2022
We messed up. We messed up big. Our contract had a flaw that allowed 2 people to scoop up over 450 NFTs.
Here is what we are doing to fix it
According to RPF, their smart contract had a flaw that saw the code exploited, allowing the bandits to allocate more than the allowed number of NFTs.
The RPF team made moves to rectify the situation soon after the exploit, offering one of the people involved a deal to pay them a bounty of 2.5 Ether (ETH) (worth $3,944.68 at the time of writing) to recover 330 of the NFTs, which was accepted.
The crypto investigators noted that the exploiters "did negotiate in good faith and allow us to come to a reasonable solution with them."
The free mint, titled “Bad Guys” featured artworks of NFT "scammers accidentally let loose on the blockchain."
The collection serves as a whitelist or presale for members before the upcoming 10,000 NFT collection this fall.
Holding a Bad Guy NFT provides exclusive access to the mint, the RPF main drop, and other upcoming projects.
Warnings ignored
The watchdog group admitted that the exploit occurred as they didn’t heed warnings from an unknown source about the potential flaws sent 30 minutes before the mint went live.
"After reviewing it with three different dev teams, we did not believe the credibility of the information sent to us... We were clearly wrong, and we are truly, truly sorry."
As discussed on our Twitter space's earlier today -
— Rug Pull Finder (@rugpullfinder) September 2, 2022
We messed up. We messed up big. Our contract had a flaw that allowed 2 people to scoop up over 450 NFTs.
Here is what we are doing to fix it
The NFT investigator pointed to digital blockchain creative agency Doxxed Media as having handled all the art and contract work, and they "did not have our team audit it, or an independent 3rd party."
The irony of the exploit has not been missed by the crypto community, with some praising the NFT investigator for admitting to its fault, while others have questioned how a company specializing in detecting smart contract vulnerabilities didn’t conduct the proper checks on its own project.
I think its concerning when security minded projects like RugPullFinder get their discord breached and their code exploited yet they're offering those exact services to customers. What do you think? pic.twitter.com/zJRWUXqic5
— OKHotshot (@NFTherder) September 2, 2022
After the shaky start however, RPF has managed to get their NFT project back on track.
Through consultation with their online community, RPF has decided to distribute the recovered NFTs across a variety of spaces, including in the "Bad Guys Vault," a raffle on Twitter, and two further raffles for projects that are friends of Rug Pull Finder and the Rug Pull Finder public sale wallet collection list.
Information on these pages contains forward-looking statements that involve risks and uncertainties. Markets and instruments profiled on this page are for informational purposes only and should not in any way come across as a recommendation to buy or sell in these assets. You should do your own thorough research before making any investment decisions. FXStreet does not in any way guarantee that this information is free from mistakes, errors, or material misstatements. It also does not guarantee that this information is of a timely nature. Investing in Open Markets involves a great deal of risk, including the loss of all or a portion of your investment, as well as emotional distress. All risks, losses and costs associated with investing, including total loss of principal, are your responsibility. The views and opinions expressed in this article are those of the authors and do not necessarily reflect the official policy or position of FXStreet nor its advertisers.
Recommended Content
Editors’ Picks
Litecoin Price Prediction: LTC tries to retake $100 resistance as miners halt sell-off
Litecoin price grazed 105 mark on Monday, rebounding 22% from the one-month low of $87 recorded during last week’s market crash. On-chain data shows sell pressure among LTC miners has subsided. Is the bottom in?
Bitcoin fails to recover as Metaplanet buys the dip
Bitcoin price struggles around $95,000 after erasing gains from Friday’s relief rally over the weekend. Bitcoin’s weekly price chart posts the first major decline since President-elect Donald Trump’s win in November.
SEC Commissioner Hester Pierce sheds light on Ethereum ETF staking under new administration
In a Friday interview with Coinage, SEC Commissioner Hester Peirce discussed her optimism about upcoming regulatory changes as the agency transitions to new leadership under President Trump’s pick for new Chair, Paul Atkins.
Bitcoin dives 3% from its recent all-time high, is this the cycle top?
Bitcoin investors panicked after the Fed's hawkish rate cut decision, hitting the market with high selling pressure. Bitcoin's four-year market cycle pattern indicates that the recent correction could be temporary.
Bitcoin: 2025 outlook brightens on expectations of US pro-crypto policy
Bitcoin price has surged more than 140% in 2024, reaching the $100K milestone in early December. The rally was driven by the launch of Bitcoin Spot ETFs in January and the reduced supply following the fourth halving event in April.
Best Forex Brokers with Low Spreads
VERIFIED Low spreads are crucial for reducing trading costs. Explore top Forex brokers offering competitive spreads and high leverage. Compare options for EUR/USD, GBP/USD, USD/JPY, and Gold.