News

July 30, 2025

NFT Platform SuperRare’s $730K Exploit: A Case of Inadequate Smart Contract Testing

"Stylized coding bug signifying exploit on SuperRare's NFT trading platform against a dark digital backdrop, showing RARE tokens being stolen and a stressed text overlay of the severe $731,000 value threat, accented with orange, dark and midnight blue brand colors, amid subtly interwoven binary code."

SuperRare’s Smart Contract Bug Brings Loss of RARE Tokens

SuperRare, an NFT trading platform, underwent a setback with its smart contract causing a consequential loss of $730,000. It is reported that the smart contract bug was a basic mistake that could have been avoided if proper testing methods were practiced. The void in the system allowed hackers to exploit SuperRare’s staking contract and siphon around $731,000 worth of RARE tokens, leading to a massive heist in the world of cryptocurrency.

Mercle Root Vulnerability

The loophole that led to this misfortune was traced back to a function designed to restrict interaction with the Merkle root. A Merkle root is a critical data component that maintains the user staking balances. In the case of SuperRare, this function was incorrectly coded, which instead allowed any address to interact with it. The oversight proved costly for the NFT trading platform, stirring discussions throughout the crypto community. One such discussion was led by 0xAw, the lead developer at decentralized exchange Alien Base, who remarked that the error was glaring enough to be caught by ChatGPT. After independent verification, it was confirmed that OpenAI’s o3 model could successfully identify the flaw at testing.

Experts Weigh in on the Misstep

Criticizing the gap in testing, 0xAw emphasized that any competent Solidity developer or «chatbot» such as ChatGPT could have caught the glaring mistake had they looked. Affirming 0xAw’s statement, Mike Tiutin, Chief Technology Officer at firm AMLBot, stated that the error was due to the lack of proper testing by the developers. AMLBot CEO Slava Demchuk also emphasized the necessity of extensive testing and bug bounty programs that could have potentially caught the bug ahead of deployment.

SuperRare Assures Safety Measures

Responding to the mishap, SuperRare’s co-founder Jonathan Perkins assured that despite the setback, no core protocol funds had been lost. He further mentioned that the affected users would be compensated for their losses and stated that a total of 61 wallets were affected by this exploit. Perkins admitted that the bug made it through despite audits and unit testing, conceding that it was introduced late in the development process and was not part of final test scenarios.

The Role of Unit Tests in Software Development

Unit tests serve as a critical component in software development, particularly with the growing prevalence of cryptocurrency and smart contracts. They are automated tests that verify individual parts of a program, usually functions or methods, and confirm they work as expected based on input parameters. In this scenario, the purpose of unit tests would be to validate whether addresses are permitted to call the function alternating the Merkle root or not. This oversight, or rather the lack of extensive testing, paved the way for a vulnerability that cost SuperRare dearly.

Addressing Future Issues and Implementing Solutions

Following the setback, Perkins has stated that SuperRare will mandate re-audits for future post-audit changes, no matter how small, as part of their updated workflow. Analysts and blockchain experts insist that such mistakes can be avoided effectively via extensive testing. While unfortunate, situations such as these serve as a reminder in the digital currency space that testing methodologies need to be robust to minimize vulnerabilities in crypto platforms.
James Carter

Financial Analyst & Content Creator | Expert in Cryptocurrency & Forex Education

James Carter is an experienced financial analyst, crypto educator, and content creator with expertise in crypto, forex, and financial literacy. Over the past decade, he has built a multifaceted career in market analysis, community education, and content strategy. At AltSignals.io, James leads content creation for English-speaking audiences, developing articles, webinars, and guides that simplify complex market trends and trading strategies. Known for his ability to make technical finance topics accessible, he empowers both new and seasoned investors to make informed decisions in the ever-evolving world of digital finance.

Latest posts by James Carter

Latest posts from the category News