NFTGem protocol exploited via reentrancy vulnerability in createClaims function; $16K lost, $3.9K rescued by Defimon.
Security & Exploits ·
The NFTGem protocol sustained a loss of approximately $16,000 following a reentrancy exploit on Binance Smart Chain, though a bot run by Defimon identified and rescued around $3,900 from eight vulnerable pools. The protocol's factory contract generated pools susceptible to reentrancy attacks, and after the initial compromised transaction, multiple bots began scanning for additional vulnerable instances.
The vulnerability exists in the createClaims function of NFTGem's pool contracts, which executes an ERC1155 mint operation before updating key state variables including claim amounts and timestamps. An attacker exploited the onERC1155Received callback to re-enter the function, generating a second claim with an identical hash while the counter remained unincremented. This allowed the outer call to overwrite the claim amount with a higher-cost short-timeframe deposit (28.718 BNB), displacing the inner call's cheaper amount (21.912 BNB), and enabled redemption of both NFT units at the inflated rate, yielding approximately 6.8 BNB in profit.
Defimon located the protocol owners through GitHub and returned the recovered funds. The scope of total funds across all vulnerable pools and whether additional rescue efforts are ongoing remain unclear.