Chainlink Callback Exploit Hits TokenWorks, CryptoPunk Lost

A vulnerability in TokenWorks’ Fake World Assets (FWA) protocol has allowed an attacker to manipulate an NFT purchase, prompting the team to suspend trading activity and compensate the owner of the affected asset. According to TokenWorks founder Adam, the exploit involved front-running a Chainlink callback that determined which NFT would be selected from a pooled … Continue reading Chainlink Callback Exploit Hits TokenWorks, CryptoPunk Lost