Revoke.cash logo

Quixotic Hack

Check if your address is affected.

1 Jul 2022
$150k stolen
Optimism Logo

Quixotic was the largest NFT marketplace on Optimism. Besides buying listed NFTs, users could make offers on NFTs using tokens, which meant approving Quixotic's exchange contract to spend those tokens. On 1 July 2022, shortly after a contract update, an attacker found that the contract checked that the seller had signed off on a sale, but not that the buyer had agreed to it. That let them sell worthless NFTs to any wallet that had approved the contract and make it pay with its approved tokens.

The attacker took around $150k worth of tokens, all on Optimism. NFTs themselves were not affected. Within a few hours, Quixotic paused all marketplace activity, told users to cancel their open offers, and promised to refund all stolen tokens, and it went on to refund the affected users. Ownership of the exchange contract has since been renounced, which means nobody is able to switch the paused contract back on.

Because the contract is permanently paused and nobody controls it anymore, this exploit can no longer be used to take tokens from your wallet. Still, if you ever made offers on Quixotic, any approvals you gave to its old exchange contract no longer serve a purpose, and revoking them is good hygiene. Keeping only the approvals you actively need limits the damage if another contract you have approved turns out to be flawed.

Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.

Next time, revoke it automatically

Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.

See how Auto-Revoking works →
Get Ultimate
Back to Exploits