Features

Meet the 16-Year-Old Dev Who Became a Hero in the NFT Trader Exploit

BY Lorepunk & Erika Lee

December 18, 2023

In the wake of the major hack that occurred on Dec. 16, where a pair of aging contracts on the trading platform NFT Trader fell victim to exploitation, a hacker succeeded in making off with a trove of high-value NFTs, including assets like Bored Apes, Art Blocks, and World of Women. Amid this chaos, an unlikely hero emerged.

As we already know, Foobar, also known as 0xfoobar, the founder of Delegate, was imperative in helping decipher the faulty code; he also had help from a talented 16-year-old coder named Fade. Together, they embarked on a time-sensitive mission to uncover the vulnerabilities within NFT Trader’s compromised contracts and played a crucial role in eliminating the exploits.

The nft now team caught up with Fade, the young dev who lent his expertise to this critical endeavor. While Fade has chosen to stay anonymous and not reveal any personal details that might compromise his identity, our interview delves into his perspective on the events to gain insight into the extraordinary efforts that helped safeguard millions of dollars worth of digital assets.

Fade’s Perspective

nft now: How did you first get into coding and web3?

Fade: I’ve been experimenting with little scripts for a few years, mostly stemming from thoughts like “How can I make this easier?” My interest toward crypto came initially from seeing it used as a payment method, from where I learned more about the ecosystem and also witnessed the rise of web3 (have been lurking for a while) and the access to the system it can provide to individuals like myself.

How do you balance web3 with your day-to-day life as a 16-year-old?

It’s definitely a challenge to keep myself up to date with everything in the space, but I try and manage. Finding the right accounts to follow is the key.

Can you walk us through the sequence of events from your perspective?

I’d first discovered the exploit pretty early on through a tweet on my timeline and was actively watching the main exploiter steal valuable NFTs one by one. Then, the attacks stopped. The NFT Trader multisig had paused the contract to prevent any more NFTs from being stolen, and I thought that was it.

How did you discover what was going on with the NFT Trader contract exploit, and what made you decide to dive into the code and figure out a solution?

A little while later, I saw that NFTs were still being stolen, and it turned out there was another contract being exploited. That’s what made me go into the code; I was curious why the contract wasn’t paused and came to the same conclusion Foobar did.

Foobar had tweeted about having a way to pause the contract, which made me go back into the code and see why he thought that. It turns out he thought the contract had a function that it didn’t, while I was thinking he knew that. While trying to find Foobar’s way of pausing, I found a potential way to pause it, thinking it was the same way Foobar had found.

Soon after Foobar tweeted his correction, I replied with it. I actually deleted the reply at first, thinking I was wrong, but I decided to go with it anyway. Soon after, Foobar confirmed I was right, and he wrote the simple contract to stop any malicious transaction to the contract. It felt great not to be wrong.

“I actually deleted the reply at first, thinking I was wrong, but I decided to go with it anyway.”

Fade

Were you involved in working on the fix directly at all, liaising with Foobar and NFT Trader?

I wasn’t involved with getting it fixed other than the idea, but the fix soon reached NFT Trader, who quickly put it to use.

Was this your first time helping out in the case of an exploit and working with Foobar?

This weekend was the first time I’d “helped out” with an exploit, though I’ve been tracking various exploits/MEV happenings for a while now.

As for Foobar, I’ve been following him for quite some time; though I don’t know him personally, I have been impressed with how he can quickly spin up things that people can use, like showcased this weekend but also, for example, having made an ERC-20 wrapper for Friendtech shares.

What’s the response been like to your hard work?

The response has been amazing – my follower count has gone up 40 times, have countless DMs thanking me and encouraging me, which do include some work offers, which was surprising since I feel like I didn’t do much. It feels like I’ve gotten a new push to find more good things to do.

How do you hope to use your coding skills in the future?

In the (perhaps near) future, I hope to contribute more to open-source software and public goods, and who knows, maybe spin up something of my own.

“I hope to contribute more to open-source software and public goods, and who knows, maybe spin up something of my own.”

FADE

What security steps should platforms and users take to avoid these exploits in the future?

My advice to users for keeping funds safe would be to take advantage of the recent advancements in the scene, with stuff like Foobar’s own Delegate, MetaMask Snaps, Rabby and, of course, to keep approvals in check on Revoke; doing so could have saved a lot of funds this weekend. Protocols should also invest in high-quality audits.

Additional reporting by Matt Medved

Dive Deep

Features & Guides