CryptoReal
CASE FILE — Mar 3, 2022

A Missing Quantity Check Let an Attacker Walk Off With $1.4M in Treasure DAO NFTs

Treasure DAO, the largest NFT marketplace on Arbitrum, lost approximately $1.4 million worth of NFTs to an exploiter on Thursday, March 3, 2022. In response, the team advised affected users to delist their remaining NFTs while the effort to trace the pseudonymous attacker got underway.

01The Vulnerability

The theft stemmed from a logic flaw in the marketplace's buyItem function, which failed to verify that the purchase quantity was greater than zero. As security researcher harry.eth pointed out, the exploiter simply called buyItem() requesting zero quantity, paid nothing, and still received the listed NFT.

The fix was trivial — a single validation check requiring the quantity parameter to exceed zero would have closed the hole entirely.

Once exploitation began, Treasure DAO paused the marketplace, causing further transactions to fail. Co-founder John Patten (Pattern) committed to covering the losses personally, stating he would give up his entire Smols collection to help make things right.

Sums referenced in this case file

Evidence of the affected listings can still be traced through Treasure DAO's marketplace activity feed — the Smol Brains collection offers one example, viewable in its recent activity log. At the time of the exploit, that collection's floor price sat around 2,500 MAGIC, worth just over $9,000.

Following news of the hack, MAGIC, the project's token, dropped by roughly a third before stabilizing, ultimately settling around 10% below its pre-incident price.

02Recovery Efforts

Within hours, on-chain sleuths said they had linked one of the exploiter's accounts to an ENS name and Binance-associated addresses. Facing that exposure, the attacker began returning a number of the stolen NFTs, suggesting the threat of being publicly identified outweighed the benefit of holding largely illiquid assets.

Treasure DAO later issued a statement on Twitter, thanking the community for its support during the exploit and noting the team was focused on locating the roughly 50 NFTs still unaccounted for, with the goal of making affected buyers whole.

03Aftermath

The MAGIC token rallied quickly following the incident, and combined with a broadly supportive community reaction, the project appears unlikely to be derailed by the loss. Still, given scrutiny surfacing around some individuals connected to the project, along with the basic nature of the coding error that enabled the exploit, some observers suggested caution going forward for those holding assets on the platform.

NFTTreasure DAO
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.