NFT

NFT Community Loses $400K USD In Premint Compromise

Included in the 300 plus stolen NFTs were assets from BAYC, Moonbirds, and more.

NFT

NFT Community Loses $400K USD In Premint Compromise

Included in the 300 plus stolen NFTs were assets from BAYC, Moonbirds, and more.

Late Saturday, July 16, the NFT access list solution platform Premint was hacked. The scam consisted of a false raffle that prompted users to sign a MetaMask transaction giving hackers permission to access all assets. As a result, nearly $400k USD in digital assets were stolen.

Among the assets were NFTs from popular projects like the Bored Ape Yacht Club, Moonbirds, Doodles, VeeFriends, and more. The raffle page itself looked like any other you might find when using Premint — however, the transaction required to sign is where users were taken advantage of.

Twitter communities acted as quickly as they could the night of the hack, to warn their users and advised any who might have signed the transaction to use revoke.cash, a site that disconnects wallets and associated permissions from potentially malicious platforms.

As a result of the compromise, discussions surrounding user experience (UX) and user interfaces (UI) were sparked. As of now, the steps to sign a transaction on MetaMask that gives the requester permission to access all digital assets in a user’s wallet looks the same as any other transaction.

In a tweet regarding this issue, Premint’s CEO Brenden Mulligan called out the UI issue and later said he would be willing to work with MetaMask to develop a better experience.

With the lack of a built-in warning system on dapps like MetaMask and UniSwap a few independent coders in the Web3 community have taken it upon themselves to build an extension that does exactly that. Web3 engineers Nish and Justin Phu have built what they’re calling PocketUniverse — an extension that gives retail users clear warnings of scams and potentially malicious transactions.

The question from the broader community is not if better UI is needed, but when will it be provided. It is becoming increasingly clear that for Web3 adoption to expand, less technical UX and UI will be required.

At the time of writing, Premint said it is investigating the situation further but has not provided any updates beyond that. To put consumer worries to rest, the platform has implemented a sign-in function that does not require the linking of any wallet.

In other news, RTFKT x Nike’s AR hoodie is set to launch this week.

You may also like

Azuki Hack Results in Over $750K USD in Stolen Funds
NFT

Azuki Hack Results in Over $750K USD in Stolen Funds

Serving as yet another example of why users should proceed with caution and use security tools.
Courtyard on a Mission To Bring $400B USD Collectibles Market On-Chain
NFT

Courtyard on a Mission To Bring $400B USD Collectibles Market On-Chain

By securely storing high-value physical assets in Brink’s vaults and bringing to life digital counterparts through advanced 3D scans minted as NFTs.
Yuga Labs’ BTC NFT Auction Sees $16.5M USD in 24 Hours
NFT

Yuga Labs’ BTC NFT Auction Sees $16.5M USD in 24 Hours

With winning bids ranging from 2.5 BTC to 7 BTC and overall mixed feedback from the Web3 community.
NFTs See Nearly $1B USD in January Sales Volume
NFT

NFTs See Nearly $1B USD in January Sales Volume

Begging the question, bull run or bull trap? As well as, what might have led to the resurgence.
More ▾