PREMINT Frontend Hack
Check if your address is affected.
PREMINT is a popular NFT registration platform, where collectors connect their wallets to sign up for NFT projects. On 17 July 2022, hackers managed to inject malicious code into the official PREMINT website. Visitors were shown a fake pop-up asking them to verify that they owned their wallet. Approving it actually gave the hackers' wallets permission to move all of their NFTs in a given collection, which the hackers then used to take them.
The hackers took around 320 NFTs, including pieces from Bored Ape Yacht Club and Otherside, and quickly sold most of them for more than $400k. PREMINT reimbursed affected users with about 340 ETH, worth around $525k at the time, based on the floor price of each stolen NFT. It also bought back the two most valuable stolen NFTs, a Bored Ape and an Azuki, from their new owners and returned them. PREMINT then announced it was acquiring Vulcan, a wallet verification tool, to improve security.
Although victims were paid back, many of them never revoked the approvals they gave to the attackers' wallets. Those approvals still let the attackers take any NFTs from the same collections that end up in those wallets later. If you approved a verification prompt on PREMINT around July 2022, check for NFT approvals to the listed attacker addresses and revoke them. Be careful with approval requests even on sites you trust, because a hacked website looks exactly like the real one.
Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.
Next time, revoke it automatically
Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.
See how Auto-Revoking works →