Wednesday, 30 Jul 2025
  • My Feed
  • My Interests
  • My Saves
  • History
  • Blog
Subscribe
Crypto Guide Daily
  • Home
  • Credit & Loans
    Credit & LoansShow More
    Why Beyoncé and Jay-Z Took Out a Second Mortgage

    When you hear the phrase “second mortgage,” a negative connotation likely comes…

    By Mia Schneider
    Fannie Mae Forecasts Lower Mortgage Rates, Less Home Price Appreciation in 2026

    While it’s a difficult concept to wrap one’s head around, it is…

    By Mia Schneider
    Home Builders Are Advertising Monthly Payments Instead of Home Prices to Clear Inventory

    Once upon a time, it was pretty common to see a new…

    By Mia Schneider
    The Magic Mortgage Rate Is Now 6%

    Ever since mortgage rates surged from their record lows in early 2022,…

    By Mia Schneider
    UWM Launches Borrower-Paid Temporary Buydown for Refinances

    The nation’s top mortgage lender has launched a new borrower-paid temporary buydown…

    By Mia Schneider
  • Finance
    FinanceShow More
    Need to Increase No. Large & Midcap Stocks by Widening Categorization? And How to Do it?

    I have maintained that there is a need to relook at the…

    By Ethan Walker
    Making Sense of Overlap among active Smallcap Funds

    There is significantly less portfolio overlap among active Smallcap Funds than among…

    By Ethan Walker
    Rethinking Retirement + Is Retirement is the real enemy of longevity?

    Most people view “retirement” as a sharp break – working full-time one…

    By Ethan Walker
    Comparing the Overlaps between major indices of Nifty50, Next50, Nifty100 and Nifty500.

    Let’s compare the Overlaps between major indices of Nifty50, Next50, Nifty100 and…

    By Ethan Walker
    Quoted (Moneycontrol) – June 2025 – How to maximise Home loan interest savings with prepayments?

    I was recently quoted in Moneycontrol in an article titled “Home loan…

    By Ethan Walker
  • Financial Tools & Apps
    Financial Tools & AppsShow More
    How I Stay Disciplined With Money Without Being Perfect

    Let’s be honest: you don’t need another “perfect budget” template or some…

    By Sofia Martins
    Why Risk Tolerance Questionnaires Can Be Powerful For Prospects (Not Just Clients)

    For the last 20 years, Risk Tolerance Questionnaires (RTQs) have served as…

    By Sofia Martins
    Weekend Reading For Financial Planners (July 26–27)

    Enjoy the current installment of "Weekend Reading For Financial Planners" – this…

    By Sofia Martins
    Kitces & Carl Ep 169: IS There A Future Of Financial Planning In The AI Era?

    From the advent of personal computers and the Internet to smartphones and…

    By Sofia Martins
    Saying “I Don’t Know” With Confidence In Client Meetings – And Still Strengthen Trust

    For newer financial advisors, few situations feel more daunting than being asked…

    By Sofia Martins
  • Investing
    InvestingShow More
    5 Best-performing Canadian Pharma Stocks of 2025

    From established players to up-and-coming firms, Canada's pharmaceutical company landscape is diverse…

    By Emily Johansson
    Top 5 Canadian Lithium Stocks of 2025

    As the global push toward electrification accelerates, lithium remains a critical piece…

    By Emily Johansson
    Sranan Gold: Unlocking Suriname’s Next Multi-Million-Ounce Discovery in the Guiana Shield

    Sranan recently discovered new mining activity by local miners on strike of…

    By Emily Johansson
    Steve Barton: Gold, Silver, Uranium — Price Targets and Key Levels to Watch

    During an interview with the Investing News Network's Charlotte McLeod, Steve Barton…

    By Emily Johansson
    Uranium Price Update: Q2 2025 in Review

    The uranium market entered Q2 on shaky footing, with spot prices slipping…

    By Emily Johansson
  • Crypto
    CryptoShow More
    Ethereum Leads Futures Rebound As Top Altcoin OI Nears $45B

    Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad…

    By Sofia Martins
    Bitcoin Buying Spree Ends On Coinbase: Temporary Pause Or Trend Shift?

    Data shows the Bitcoin Coinbase Premium Gap recently broke its longest ever…

    By Sofia Martins
    Bitcoin Price Holds Steady – Range-Bound Action Dominates Price Chart

    Bitcoin price is still holding the $117,250 support zone. BTC is consolidating…

    By Sofia Martins
    Key Player In $13M Crypto Ponzi Pleads Guilty

    A major player in a crypto Ponzi scheme that duped victims out…

    By Sofia Martins
    Stablecoin Google Searches Hit All-Time High as GENIUS Act Fuels $272B Market Surge

    Global interest in stablecoins has hit unprecedented levels, with Google searches for…

    By Sofia Martins
  • 🔥
  • Crypto
  • Investing
  • Finance
  • Credit & Loans
  • Financial Tools & Apps
Font ResizerAa
Crypto Guide DailyCrypto Guide Daily
  • My Saves
  • My Interests
  • My Feed
  • History
Search
  • Home
  • Credit & Loans
  • Finance
  • Financial Tools & Apps
  • Investing
  • Crypto
  • Personalized
    • My Feed
    • My Saves
    • My Interests
    • History
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Crypto Guide Daily > Blog > Crypto > SuperRare $730,000 exploit was easily preventable — Experts weigh in
Crypto

SuperRare $730,000 exploit was easily preventable — Experts weigh in

Sofia Martins
Last updated: July 29, 2025 2:47 pm
Sofia Martins
Share
SHARE

Contents
Anatomy of a vulnerabilityThe importance of unit testingMost vulnerabilities are oversights

NFT trading platform SuperRare suffered a $730,000 exploit on Monday due to a basic smart contract bug that experts say could have easily been prevented with standard testing practices.

SuperRare’s (RARE) staking contract was exploited on Monday with around $731,000 worth of RARE tokens stolen, according to crypto cybersecurity firm Cyvers.

The vulnerability stems from a function meant to allow only specific addresses to modify the Merkle root, a critical data structure that determines user staking balances. However, the logic was mistakenly written to allow any address to interact with the function.

0xAw, lead developer at Base decentralized exchange Alien Base, pointed out that the mistake in question was obvious enough to be caught by ChatGPT. Cointelegraph independently verified that OpenAI’s o3 model successfully identified the flaw when tested.

Security, Hackers, Cybersecurity, Hacks
Relevant code in the SuperRare token staking contract. Source: Cointelegraph

“ChatGPT would’ve caught this, any half competent Solidity dev would’ve caught this. Basically anyone, if they looked. Most likely nobody did,” 0xAw told Cointelegraph.

SuperRare co-founder Jonathan Perkins told Cointelegraph that no core protocol funds were lost, and affected users will be made whole. He said that it appears that 61 wallets are affected.

“We’ve learned from it, and now future changes will go through a much more robust review pipeline,“ he said.

Related: Crypto hacks surpass $3.1B in 2025 as access flaws persist: Hacken

Anatomy of a vulnerability

To determine whether changing the Merkle root should be allowed, the smart contract checked if the interacting address was not a specific address or the contract’s owner. This is the opposite logic to what was intended to be enforced, allowing anyone to siphon the staked RARE out of the contract.

Security, Hackers, Cybersecurity, Hacks
The line containing the relevant check. Source: Cointelegraph

A senior engineer at crypto insurance firm Nexus Mutual told Cointelegraph that “unit tests would have caught this mistake.”

Mike Tiutin, blockchain architect and chief technology officer at firm AMLBot, said, “It’s a silly mistake of the developer that was not covered by tests (that’s why full coverage is important).”

AMLBot CEO Slava Demchuk also came to the same conclusion, noting that “there was no extensive testing (or a bug bounty program) that could have found it pre-deployment.” He highlighted the importance of testing, noting that it is a “classic example why smart contract logic must be rigorously audited.” He added:

“This stands as a stark reminder: in decentralized systems, even a one-character mistake can have severe consequences.”

While Perkins insisted the contracts were audited and unit-tested, he acknowledged that the bug was introduced late in the process and wasn’t covered in final test scenarios:

“It’s a painful reminder of how even small changes in complex systems can have unintended consequences.“

Related: Indian crypto exchange CoinDCX hacked, $44M drained

The importance of unit testing

Unit tests are small, automated tests that check whether individual parts (“units”) of a program — typically functions or methods — work as expected. Each test targets a specific behavior or output based on a given input, helping to catch bugs early.

In this case, the tests that verify whether addresses can or cannot call the function to modify the Merkle root would have failed.

“By oversight or inadequate testing, the effect was the same: an avoidable vulnerability that cost massively,“ Demchuk told Cointelegraph.

0xAw similarly said that “the problem was, of course, the apparently complete lack of testing.” He said that “it’s not even a kind of code that works well in normal conditions, and fails if you push it in the right places.”

“This code just does the opposite of what you expect,“ he added.

Perkins told Cointelegraph that moving forward, SuperRare has introduced new workflows that mandate re-audits for any post-audit changes, no matter how minor.

Most vulnerabilities are oversights

0xAw said that the mistake is “a normal human error.” Instead, what he views as a “monumental mistake” is that it “made it to production and stayed there.”

0xAw highlighted that the vast majority of serious vulnerabilities originate from “really stupid and easily preventable mistakes.” Still, he admitted that “they’re usually a bit harder to notice than this.”

Hacken’s head of incident response, Yehor Rudytsia, agreed that thorough test coverage would have caught the flaw.

“If reviewing this function, it’s a pretty obvious bug,” he said.

Magazine: North Korea crypto hackers tap ChatGPT, Malaysia road money siphoned: Asia Express

Share This Article
Twitter Email Copy Link Print
Previous Article Why is India investigating Binance and WazirX over crypto loopholes?
Next Article Ethereum Sta Diventando Parte della Finanza Tradizionale (TradFi) — Ecco Perché
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Informed with Verified and Up-to-the-Minute Information

We are committed to accuracy, impartiality, and delivering breaking news as it unfolds—earning the trust of a wide and discerning audience. Stay informed with real-time updates on the latest events and emerging trends.
FacebookLike
TwitterFollow
PinterestPin
InstagramFollow
MediumFollow
QuoraFollow

You Might Also Like

Crypto

BitMine Drops After SEC Filing for Share and Warrant Resale

By Sofia Martins
Crypto

Drawdown Analysis Shows No Signs Of Panic

By Sofia Martins
Crypto

What Ripple CEO Garlinghouse Will Tell the US Senate Today

By Sofia Martins
Crypto

Ethereum Price Fails to Hold Momentum Above $3K — Correction Ahead?

By Sofia Martins
Crypto Guide Daily
Facebook Twitter Youtube Rss Medium

About Us

CryptoGuideDaily: Your gateway to the fast-paced world of cryptocurrency. Get real-time updates, expert insights, and breaking news across Bitcoin, Ethereum, DeFi, NFTs, and more. Stay informed with 24/7 crypto coverage.

Top Categories
  • Financial Tools & Apps
  • Credit & Loans
  • Finance
  • Investing
  • Crypto
  • Terms and Conditions
Usefull Links
  • Advertise with US
  • Privacy Policy
  • History
  • My Saves
  • My Interests
  • My Feed
  • Contact
  • About us
  • Sitemap
  • Terms and Conditions

© Crypto Daily Guide. All Rights Reserved.

  • bitcoinBitcoin(BTC)$117,947.00-0.32%
  • ethereumEthereum(ETH)$3,812.600.89%
  • rippleXRP(XRP)$3.140.12%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$806.48-1.87%
  • solanaSolana(SOL)$181.52-0.95%
  • usd-coinUSDC(USDC)$1.000.00%
  • staked-etherLido Staked Ether(STETH)$3,810.540.94%
  • dogecoinDogecoin(DOGE)$0.224274-0.36%
  • tronTRON(TRX)$0.3376674.19%
  • cardanoCardano(ADA)$0.79-0.35%
  • Wrapped stETHWrapped stETH(WSTETH)$4,606.490.97%
  • wrapped-bitcoinWrapped Bitcoin(WBTC)$117,865.00-0.35%
  • HyperliquidHyperliquid(HYPE)$43.36-0.33%
  • suiSui(SUI)$3.82-2.74%
  • stellarStellar(XLM)$0.4209340.38%
  • wrapped-beacon-ethWrapped Beacon ETH(WBETH)$4,096.471.49%
  • chainlinkChainlink(LINK)$17.87-1.29%
  • bitcoin-cashBitcoin Cash(BCH)$569.78-1.85%
  • hedera-hashgraphHedera(HBAR)$0.259837-2.73%
  • Wrapped eETHWrapped eETH(WEETH)$4,088.770.95%
  • avalanche-2Avalanche(AVAX)$24.32-2.17%
  • WETHWETH(WETH)$3,815.790.99%
  • litecoinLitecoin(LTC)$108.970.15%
  • leo-tokenLEO Token(LEO)$8.96-0.12%
  • the-open-networkToncoin(TON)$3.415.70%
  • Ethena USDeEthena USDe(USDE)$1.000.01%
  • shiba-inuShiba Inu(SHIB)$0.000013-1.64%
  • USDSUSDS(USDS)$1.000.00%
  • Binance Bridged USDT (BNB Smart Chain)Binance Bridged USDT (BNB Smart Chain)(BSC-USD)$1.000.10%
  • whitebitWhiteBIT Coin(WBT)$44.10-0.20%
  • Coinbase Wrapped BTCCoinbase Wrapped BTC(CBBTC)$117,989.00-0.31%
  • uniswapUniswap(UNI)$10.460.96%
  • polkadotPolkadot(DOT)$3.90-1.73%
  • moneroMonero(XMR)$316.23-0.43%
  • bitget-tokenBitget Token(BGB)$4.56-0.27%
  • pepePepe(PEPE)$0.000012-2.36%
  • crypto-com-chainCronos(CRO)$0.143460-1.18%
  • Ethena Staked USDeEthena Staked USDe(SUSDE)$1.190.01%
  • aaveAave(AAVE)$283.54-1.41%
  • daiDai(DAI)$1.000.00%
  • EthenaEthena(ENA)$0.58-5.22%
  • BittensorBittensor(TAO)$382.82-4.19%
  • nearNEAR Protocol(NEAR)$2.720.37%
  • ethereum-classicEthereum Classic(ETC)$21.820.34%
  • Pi NetworkPi Network(PI)$0.427223-2.46%
  • aptosAptos(APT)$4.56-1.26%
  • OndoOndo(ONDO)$0.96-2.29%
  • internet-computerInternet Computer(ICP)$5.44-1.33%
  • Jito Staked SOLJito Staked SOL(JITOSOL)$221.70-0.84%
  • okbOKB(OKB)$48.10-1.14%
  • mantleMantle(MNT)$0.77-1.35%
  • kaspaKaspa(KAS)$0.095563-1.50%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • Pudgy PenguinsPudgy Penguins(PENGU)$0.037477-6.64%
  • Binance-Peg WETHBinance-Peg WETH(WETH)$3,821.731.10%
  • algorandAlgorand(ALGO)$0.260857-0.48%
  • bonkBonk(BONK)$0.000029-8.57%
  • USD1USD1(USD1)$1.00-0.16%
  • arbitrumArbitrum(ARB)$0.424237-0.97%
  • vechainVeChain(VET)$0.0252092.41%
  • gatechain-tokenGate(GT)$17.65-1.09%
  • cosmosCosmos Hub(ATOM)$4.58-0.59%
  • render-tokenRender(RENDER)$3.91-3.18%
  • polygon-ecosystem-tokenPOL (ex-MATIC)(POL)$0.221705-2.12%
  • fasttokenFasttoken(FTN)$4.59-0.06%
  • worldcoin-wldWorldcoin(WLD)$1.08-2.07%
  • Official TrumpOfficial Trump(TRUMP)$9.48-1.07%
  • SPX6900SPX6900(SPX)$2.00-4.36%
  • SkySky(SKY)$0.086570-3.31%
  • fetch-aiArtificial Superintelligence Alliance(FET)$0.710.24%
  • sei-networkSei(SEI)$0.317359-0.91%
  • Binance Staked SOLBinance Staked SOL(BNSOL)$193.70-0.61%
  • rocket-pool-ethRocket Pool ETH(RETH)$4,342.980.75%
  • sUSDSsUSDS(SUSDS)$1.060.02%
  • quant-networkQuant(QNT)$120.53-0.74%
  • filecoinFilecoin(FIL)$2.57-0.68%
  • flare-networksFlare(FLR)$0.0247931.26%
  • Kelp DAO Restaked ETHKelp DAO Restaked ETH(RSETH)$4,001.550.91%
  • StoryStory(IP)$5.601.75%
  • Lombard Staked BTCLombard Staked BTC(LBTC)$117,434.00-0.10%
  • Jupiter Perpetuals Liquidity Provider TokenJupiter Perpetuals Liquidity Provider Token(JLP)$5.06-0.20%
  • xdce-crowd-saleXDC Network(XDC)$0.10004612.13%
  • JupiterJupiter(JUP)$0.53-1.64%
  • kucoin-sharesKuCoin(KCS)$11.38-0.95%
  • USDtbUSDtb(USDTB)$1.000.04%
  • StakeWise Staked ETHStakeWise Staked ETH(OSETH)$4,024.830.93%
  • Mantle Staked EtherMantle Staked Ether(METH)$4,080.671.05%
  • Liquid Staked ETHLiquid Staked ETH(LSETH)$4,118.520.80%
  • injective-protocolInjective(INJ)$14.15-1.75%
  • curve-dao-tokenCurve DAO(CRV)$1.001.06%
  • USDT0USDT0(USDT0)$1.000.09%
  • CelestiaCelestia(TIA)$1.85-2.02%
  • first-digital-usdFirst Digital USD(FDUSD)$1.00-0.14%
  • nexoNEXO(NEXO)$1.320.08%
  • optimismOptimism(OP)$0.72-1.97%
  • Renzo Restaked ETHRenzo Restaked ETH(EZETH)$4,015.570.83%
  • blockstackStacks(STX)$0.78-0.30%
  • Polygon Bridged USDT (Polygon)Polygon Bridged USDT (Polygon)(USDT)$1.00-0.01%
  • Falcon USDFalcon USD(USDF)$1.000.02%
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?