The NBA’s plan to drop 18,000 free NFTs on its fans has gone awry.
The basketball league yesterday launched a new collection of NFTs called “The Association,” which was intended to provide exclusive NFTs to the earliest members of the NBA’s Discord server. Instead, security vulnerabilities in the collection’s smart contractsmart contract, the computer code that enables NFTs to be created and traded, resulted in users exploiting the drop, unfairly minting the NFT, and cleaning out the collection in roughly an hour.
The NBA yesterday acknowledged the exploit and said it would work toward a resolution for its fans. Today, the league announced it would increase the size of its NFT collection from 18,000 to 30,000 items in order to ensure everyone who was supposed to receive one will get one.
We recognize the issues with the smart contract which caused the Allow List supply to sell out prematurely. We apologize for this situation and are currently identifying the Allow List wallets that were not able to mint as a result.
NFTs, short for “non-fungible tokens,” are unique tokenstokens that are used to signify ownership over digital assets, such as artwork and other types of collectibles. In this case, each Association NFT represents an NBA player in this year’s playoffs: 75 NFTs of each player from 16 different teams, initially totaling 18,000 NFTs in all. The NFTs are meant to be "dynamic" and will change, and presumably increase or decrease in value, depending on the real-life performance of the player to which it is linked.
Each NFT was to be reserved for early members of the NBA’s Discord server, which just launched on Friday. These members were granted access to an “allow list” (another term for whitelist) that would reserve one free NFT per each Ethereumwalletwallet address registered on the list.
But bugs within The Association’s smart contract destroyed this promise to those fans. A relatively simple exploit allowed users that were whitelisted to grant minting access to other wallets that weren’t on the original allow list.
The contract also didn’t properly keep track of the number of mints that took place per wallet. “If a contract was made, it could mint the entire collection in one transaction” tweeted CaptainDefi, a Twitter user who provided an overview of the code on Wednesday.
🏴☠️ NBA NFTS EXPLOIT EXPLAINED THREAD 🏴☠️
The Association NFTs was exploited today, anyone could mint them totally for free
This all effectively resulted in some users minting as many free NFTs as they wanted, some collecting over 100, and then quickly selling them on the secondary NFT trading market OpenSea for more than 0.30 ETH (roughly $1,000 at the time).
The NBA paused the NFT drop just over an hour into the launch after realizing their smart contract had been exploited.
NBA Smart Contract Bugs🏀
Overall, the #NBA smart contract had major security bugs, overly complicated, and lacked optimization. A friend of mine told me to check out their contract and I noticed the following problems🧵
This, however, isn’t the NBA’s first go-around with NFTs. NBA Top Shot, which captures NBA highlights in the form of NFTs on the Flowblockchainblockchain, gained notoriety last year and is largely responsible for the rise in mainstream attention in sports NFT collectibles. While there’s no clear relationship with Top Shot in the NBA’s latest drop, the league had promised some extra rare Association NFTs to Top Shot collectors.
Despite yesterday's exploit, the NBA appears poised to move forward with its plans for its Association NFT collection. "We’ve identified the wallets on the Allow List that were not able to mint an NFT yesterday and will be airdropping those fans an NFT from The Association collection," a representative of the NBA announced in its official Discord server.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.
Tradable NFT stickers are launching on Telegram via The Open Network (TON).
Open Builders—the team behind viral tap-to-earn game Notcoin—and the DOGS meme coin community announced Tuesday that they have teamed up to open Sticker Shop. The Telegram mini app will sell limited edition digital sticker packs purchased via Stars, the messaging platform's native in-app currency that’s tied to Toncoin (TON).
Purchased stickers can be shared in chats and bought and sold via marketplaces (such as Getgems)...
The Pudgy Penguins floor price broke through $100,000, up more than 20% in the last 24 hours, as excitement and speculation surround the Ethereum NFT project and its upcoming token airdrop on Solana.
The collection of 8,888 Penguin NFTs broke an all-time high mark last week when it began trading around $62,000. Shortly thereafter, the project’s team announced that an ecosystem token—PENGU—will be launched on Solana in the near future, rewarding holders of the Pudgy Penguins ecosystem and beyond...
9dcc, the on-chain fashion label founded by pseudonymous crypto personality and investor gmoney, is preparing to release its latest project, the 9dcc Black Box, on December 18.
The drop, limited to 2,750 NFTs minted on Ethereum layer-2 network Base, is being billed by the crypto-native luxury brand as a blend of fashion, blockchain technology, and mystery.
Each 9dcc Black Box promises a mix of digital and physical rewards. Buyers might find an item from the label’s Collection-01, which ranges fr...