Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
  • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

OpenZeppelin Finds Cause of Recent Smart Contract Vulnerability

The OpenZeppelin team found that the vulnerability has occurred due to the problematic integration of ERC-2771 and Multicall standards.

Written By:
Gopal Solanky

Last updated: December 8, 2023 10:32 AM
Published December 8, 2023 10:32 AM
Share
Last updated: December 8, 2023 10:32 AM
Published December 8, 2023 10:32 AM
OpenZeppelin Finds Cause of Recent Smart Contract Vulnerability

While the recently found smart contract vulnerability has shaken the DeFi ecosystem, OpenZeppelin has found the root of the threat.

The vulnerability was reported by ThirdWeb on December 5, which said that it is in a commonly used open-source library. While doing further investigation into the matter, OpenZeppelin found that the vulnerability had occurred due to the problematic integration of ERC-2771 and Multicall standards.

🚨 Important Security Alert to the Community 🚨

We are publicly disclosing a critical vulnerability arising from a problematic integration of the standard ERC-2771 and self delegatecall with user input data, including but not limited to multicall. This issue poses a significant…

— OpenZeppelin (@OpenZeppelin) December 8, 2023

“We are publicly disclosing a critical vulnerability arising from a problematic integration of the standard ERC-2771 and self delegatecall with user input data, including but not limited to multicall,” said the OpenZeppelin team. “This issue poses a significant risk of address spoofing attacks for projects combining these patterns.”

OpenZeppelin has also given a brief review of the vulnerability in a blogpost and described the scope of potential attacks. The smart-contract development firm has helped several pools mitigate attacks while also noting some ongoing attacks that are exploiting the vulnerability.

As the pre-built smart-contracts including ERC-721, DropERC20, AirdropERC20, and all variants of ERC-1155, have been affected by this vulnerability, OpenZeppelin has released a new update of its contracts library as a solution.

“While the integration between these patterns remains problematic without the proper measures, the updates made to the OpenZeppelin Contracts library allow its integration in a safe and backwards compatible way,” said the firm.

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Smart Contracts
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Gopal Solanky - Crypto Research Analyst at The Crypto Times
By Gopal Solanky Sr. Crypto Journalist
Follow:
Gopal Solanky is a Research Analyst and Reporter with over 5 years of experience in DeFi, blockchain, crypto, IT, and financial markets. With a Bachelor's in Computer Applications, he brings a strong technical foundation to his analysis and reporting. Gopal focuses on breaking down complex topics for both seasoned investors and curious readers. His work has been referenced by publications like Business Insider and Vulture.com, highlighting his contributions to industry stories around topics like Huwak Tuah Memecoin and the FTX collapse.

Latest News

Brazil Blocks Polymarket, 20+ Platforms Over Gambling Violations
Brazil Blocks Polymarket, 20+ Platforms Over Gambling Violations
Chainlink Opens Data Infrastructure to Millions via AWS Marketplace
Chainlink Opens Data Infrastructure to Millions via AWS Marketplace
Black April 2026 $606M Stolen, $13B TVL Exodus in DeFi's Darkest Month
Black April 2026: $606M Stolen, $13B TVL Exodus in DeFi’s Darkest Month
BlackRock's IBIT Bitcoin ETF Cracks U.S. Top 10
BlackRock’s IBIT Bitcoin ETF Cracks U.S. Top 10
Aave DAO Proposes 25K ETH to Cover rsETH Shortfall After KelpDAO Hack
Aave DAO Proposes 25K ETH to Cover rsETH Shortfall After KelpDAO Hack

Find Us on Socials

You may also like

Balancer Attacker Moves $11.3M to BTC Via THORChain After Kelp DAO Precedent

Balancer Attacker Moves $11.3M to BTC Via THORChain After Kelp DAO Precedent

Mantle’s 30,000 ETH Loan for Aave Comes With a Strategic Catch

Mantle’s 30,000 ETH Loan for Aave Comes With a Strategic Catch

Lido Proposes 2,500 stETH to Help Aave After KelpDAO Exploit

Lido Proposes 2,500 stETH to Help Aave After KelpDAO Exploit

Circle Pushes Aave to Adjust USDC Rates After Utilization Hits 100% for 4 Days

Circle Pushes Aave to Adjust USDC Rates After Utilization Hits 100% for 4 Days

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information