Floor Protocol Hack
Check if your address is affected.
Floor Protocol, also known as Flooring Protocol, lets NFT owners lock their NFTs in the protocol in exchange for tokens that are easier to trade, making expensive NFT collections more liquid. To use it, owners approved its contracts to move their NFTs. On 17 December 2023, an attacker found a flaw in one of the protocol's helper contracts that let them move NFTs out of wallets that had approved Floor Protocol. The protocol's main contract, and the NFTs held in its vaults, were not affected by this flaw.
The attacker took NFTs worth about $1.6M, mostly Bored Apes and Pudgy Penguins, and quickly dumped them into open bids on the NFT marketplace Blur, making roughly 850 ETH. Because the NFTs were sold on so fast, owners were unlikely to get them back. The Floor Protocol team tried to contact the attacker and deployed a fix within hours of the attack. Without that quick fix, the losses could have been more than ten times larger.
The team repaired the vulnerable contract instead of shutting it down, so this specific issue is fixed and existing approvals to Floor Protocol are no longer exposed to it. Separately, in June 2026 a different flaw in Flooring's NFT pools was exploited, and Yuga Labs rescued 68 NFTs worth over $500k. That incident targeted NFTs held inside the protocol's pools rather than wallet approvals, but security researchers advised against depositing new NFTs into Flooring. As always, it is good practice to revoke approvals you no longer need.
Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.
Next time, revoke it automatically
Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.
See how Auto-Revoking works →