Web3 innovator Thirdweb has uncovered a critical security vulnerability that potentially puts hundreds of smart contracts at risk. The flaw is associated with a widely-used open-source library, impacting various pre-built smart contracts within the Web3 ecosystem. On December 4, Thirdweb disclosed the vulnerability, specifying that contracts such as DropERC20, ERC721, ERC1155 (all versions), and AirdropERC20 could be affected.
Despite no reported exploits of the vulnerability, Thirdweb’s warning serves as a proactive measure for Web3 firms to secure their smart contracts. Acknowledging the potential for substantial damage if left unaddressed, Thirdweb urged users who deployed contracts before November 22 to take independent mitigation steps or use tools provided by the company.
As part of their response to the issue, Thirdweb initiated contact with the maintainers of the open-source library and reached out to teams that might be impacted. Additionally, the firm committed to reinforcing security efforts by doubling bug bounty payouts from $25,000 to $50,000, implementing a more rigorous auditing process, and offering grants to cover contract mitigations.
While the complete details of the vulnerability remain undisclosed for security reasons, Thirdweb’s commitment to addressing the issue emphasizes the seriousness of the situation. The company, which secured $24 million in a Series A funding round with backers like Haun Ventures, Coinbase, Shopify, and Polygon in August 2022, plays a crucial role in the Web3 space. Providing smart contract deployment tools across various chains for gaming, minting, marketplaces, and wallets, Thirdweb boasts a user base of over 70,000 developers monthly.
