The peer-to-peer NFT trading platform NFT Trader has fallen victim to one of the most significant security breaches in the NFT market’s history. Attackers exploited vulnerabilities in the platform’s legacy smart contracts, making off with high-value NFTs worth approximately $3 million, including dozens of Bored Ape Yacht Club and Mutant Ape Yacht Club tokens.
The Exploit Mechanics
The attack hinged on a combination of a reentrancy vulnerability in NFT Trader’s old smart contracts and token approvals that users had never revoked. Reentrancy attacks occur when a malicious contract calls back into the vulnerable contract before the first execution completes, allowing the attacker to repeatedly drain funds or assets before the contract can update its balance. In this case, attackers leveraged longstanding permissions that users had granted to the older contracts during previous trading activity. Because these approvals were never removed, the old contracts retained the ability to transfer NFTs on behalf of their owners, even after newer, presumably more secure contracts were deployed.
Affected Systems
The scope of the theft was staggering. At least 37 Bored Ape Yacht Club NFTs, 13 Mutant Ape Yacht Club NFTs, and tokens from the VeeFriends, World of Women, and Art Blocks collections were stolen. Some of the individual Bored Apes were valued at over $300,000 each at the time of the attack. Additionally, some ETH and APE tokens were drained from affected wallets. The attack primarily impacted users who had previously conducted trades on NFT Trader and still had active permissions on the old smart contracts. Multiple copycat attackers joined the fray after the initial exploit was discovered, compounding the damage.
The Mitigation Strategy
NFT Trader’s response involved several steps. The platform updated its smart contracts to fix the reentrancy vulnerability and urgently warned users to revoke all previously granted approvals. Community members and security researchers, including the team at Revoke.cash, played a critical role in identifying how the contracts could be shut down. A Yuga Labs co-founder intervened to negotiate with the attacker, ultimately paying a ransom of 120 ETH, approximately $260,000 at the time, to recover 36 Bored Apes and 18 Mutant Apes. The attacker had demanded 3 ETH per Bored Ape and 0.6 ETH per Mutant Ape as a bounty for returning the stolen assets.
Lessons Learned
This incident exposes a systemic problem in the NFT ecosystem: the danger of lingering token approvals. When users interact with a smart contract, they often grant it permission to transfer their tokens. If that contract is later deprecated but the approvals remain active, it creates a persistent attack surface. The NFT Trader hack demonstrates that even when platforms upgrade to newer contracts, the old ones remain a liability as long as users have not explicitly revoked their permissions. Platforms must implement automated revocation mechanisms or at minimum aggressively notify users to revoke old approvals when migrating to new contracts.
User Action Required
If you have ever traded on NFT Trader or any similar peer-to-peer NFT marketplace, immediately check your wallet’s active token approvals using tools like Revoke.cash. Revoke any permissions granted to old or deprecated contracts. Make revoking approvals a regular part of your security hygiene, especially after completing trades. Additionally, consider using a dedicated wallet for trading activities so that your primary holdings remain insulated from smart contract risks. The NFT Trader breach serves as a stark reminder that in the world of digital assets, old permissions are not just forgotten — they are actively dangerous.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before making any investment decisions.
dozens of apes gone because nobody revoked approvals on contracts they stopped using months ago. painful but so preventable
Deploying new contracts without deprecating the old ones properly is negligence. The team should have migrated approvals.
hard agree on the negligence take. if you deploy new contracts you should have a migration path or at minimum a big warning banner
reentrancy in 2023 is wild. this was solved after the DAO hack. no excuse for legacy contracts to still have this vulnerability
migration path should be automatic. revoke old approvals, flag the new contract in the UI. anything less is negligence on the devs part
automatic migration is table stakes but most NFT platforms treat contract deployment as fire and forget. the BAYC team had how many months to flag this and didnt
approval_audit_ the BAYC team had months to push a migration and did nothing. Yuga had 100M in treasury and couldnt be bothered to revoke old NFT Trader approvals. negligence plain and simple
null_ptr yuga had 100m in treasury and couldnt push a migration or revoke old approvals. pure negligence
approvals are the silent killers. everyone forgets they exist after the trade is done
legacy contracts are zombies. they never die and they eat your NFTs while you sleep
legacy contracts are zombies is the most accurate description lol. they just sit there waiting for someone to forget about them
3M in apes gone because of a reentrancy bug in a contract nobody was supposed to use anymore. every NFT platform needs an active deprecation schedule not a deploy and forget model
3M in apes stolen via reentrancy in 2023. the DAO hack was 2016 and people still deploy contracts without checks-effects-interactions. OpenZeppelin literally has a ReentrancyGuard for this
revoke.cash exists specifically for this. old approvals on deprecated contracts are how NFT Trader happened. check your wallets people
revoke.cash takes 30 seconds to use. 3M in apes gone because nobody could be bothered. self custody needs UX improvements not just more security education
revoke.cash takes literally 30 seconds. 3M in apes gone because nobody could be bothered. self custody needs UX improvements not more security education tweets
legacy contracts are zombies. they never die and they eat your NFTs while you sleep. clean up after yourself devs
automatic migration should be table stakes but most NFT platforms treat contract deployment as fire and forget
reentrancy in 2023 is wild. this was solved after the DAO hack. no excuse for legacy contracts to still have this vulnerability
reentrancy draining 3m in apes during 2023 when ReentrancyGuard exists for free on github. inexcusable
reentry_2023_64 ReentrancyGuard is literally 5 lines of code in openzeppelin. shipping a contract handling BAYC vaults without it should be criminal negligence
reentry_2023_64 ReentrancyGuard is 5 lines in openzeppelin. shipping a contract handling BAYC vaults without it should be criminal negligence tbh
3M in apes gone because users never revoked old token approvals. the contracts were deprecated but still had permission to move NFTs. deploy and forget is not a security strategy
approval_revoker_ Yuga had 100M in treasury and could not build a simple approval revocation tool for their own community. the negligence is wild
Yuga had a 100M treasury from Otherside mint alone and couldnt push a simple contract migration. the community begged them for months
reentrancy in 2023 on a legacy contract. OpenZeppelin has had ReentrancyGuard for years. no excuse for any platform to still ship without it
cefi_refugee_ ReentrancyGuard has been on github since 2019. a platform handling BAYC and MAYC vaults shipping without it in 2023 is beyond lazy
lost a MAYC in this exact exploit. never even knew the old contract was still live with my approvals. revoke your approvals people. i check weekly now
reentrancy on a LEGACY contract that still had active approvals. users trusted a dead contract for years without revoking access. this is why allowance management matters
dozens of BAYC and MAYC taken. at peak those were 100+ ETH each. the 3M total feels low if you remember 2022 floor prices