{"id":18678,"date":"2022-04-05T10:45:03","date_gmt":"2022-04-05T18:45:03","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/04\/05\/news-12411\/"},"modified":"2022-04-05T10:45:03","modified_gmt":"2022-04-05T18:45:03","slug":"news-12411","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/04\/05\/news-12411\/","title":{"rendered":"NFTs Are a Privacy and Security Nightmare"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/624b7b34a288ab4bb7de3714\/master\/pass\/NFT-Privacy-Security-1317721353.jpg\"\/><\/p>\n<p><strong>Credit to Author: Eric Ravenscraft| Date: Tue, 05 Apr 2022 11:00:00 +0000<\/strong><\/p>\n<p class=\"BylineWrapper-iiTsTb hAGfXd byline bylines__byline\" data-testid=\"BylineWrapper\" itemprop=\"author\" itemtype=\"http:\/\/schema.org\/Person\"><span itemprop=\"name\" class=\"BylineNamesWrapper-dbkCxf erRIa-D\"><span data-testid=\"BylineName\" class=\"BylineName-cKXFOb UCAzg byline__name\"><a class=\"BaseWrap-sc-TURhJ BaseText-fFzBQt BaseLink-gZQqBA BylineLink-eZnyPI eTiIvU mEZDb fNdcwQ bKZMMS byline__name-link button\" href=\"\/author\/eric-ravenscraft\">Eric Ravenscraft<\/a><\/span><\/span><\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p><span class=\"lead-in-text-callout\">Venmo&#x27;s baffling decision<\/span> to turn payments into <a href=\"https:\/\/www.wired.com\/story\/i-scraped-millions-of-venmo-payments-your-data-is-at-risk\/\">a social media feed<\/a>, where <a href=\"https:\/\/www.wired.com\/story\/venmo-privacy-by-default-global-feed\/\">public transactions are the default<\/a>, has rightly been met with criticism. But at the very least, it&#x27;s always been possible to <a href=\"https:\/\/www.wired.com\/wiredinsider\/2014\/05\/this-should-be-your-first-move-on-venmo\/\">make Venmo transactions private<\/a>. Now, imagine a financial system that&#x27;s not just public by default, but can&#x27;t ever be made private, and nothing can ever be removed or deleted.<\/p>\n<p class=\"paywall\">That&#x27;s how crypto works. And for years, it&#x27;s been too seldom recognized as an issue\u2014in large part because systems like Bitcoin, Ethereum, and other crypto platforms are technically \u201canonymous.\u201d More specifically, unlike a bank or financial app, you don&#x27;t have to attach your real name, address, or other identifying information to a wallet. Sure, everyone can see what a random wallet is doing, but they don&#x27;t necessarily know <em>who<\/em> is doing it.<\/p>\n<p class=\"paywall\">NFTs, however, radically undermine this already tenuous anonymity.\u00a0<\/p>\n<p class=\"paywall\">With any new technology, one supposedly beneficial trait often comes at the expense of another. For example, one way to describe an immutable blockchain that contains a public record of every transaction is that it\u2019s a transparent way to <a data-offer-url=\"https:\/\/www.investopedia.com\/tech\/what-cryptocurrency-public-ledger\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.investopedia.com\/tech\/what-cryptocurrency-public-ledger\/&quot;}\" href=\"https:\/\/www.investopedia.com\/tech\/what-cryptocurrency-public-ledger\/\" rel=\"nofollow noopener\" target=\"_blank\">maintain accurate records<\/a>.<\/p>\n<p class=\"paywall\">Another way to describe it is as a low-privacy environment that gives, among others, <a data-offer-url=\"https:\/\/twitter.com\/skupor\/status\/1491182806764236801\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/twitter.com\/skupor\/status\/1491182806764236801&quot;}\" href=\"https:\/\/twitter.com\/skupor\/status\/1491182806764236801\" rel=\"nofollow noopener\" target=\"_blank\">law enforcement access<\/a> to the <a data-offer-url=\"https:\/\/www.wsj.com\/articles\/justice-department-says-it-seized-3-6-billion-in-stolen-cryptocurrency-exchange-hack-11644339381\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.wsj.com\/articles\/justice-department-says-it-seized-3-6-billion-in-stolen-cryptocurrency-exchange-hack-11644339381&quot;}\" href=\"https:\/\/www.wsj.com\/articles\/justice-department-says-it-seized-3-6-billion-in-stolen-cryptocurrency-exchange-hack-11644339381\" rel=\"nofollow noopener\" target=\"_blank\">transaction history of the entire network<\/a>\u2014as was the case when the US Department of Justice arrested two individuals accused of stealing $4.5 billion worth of cryptocurrency. Said assistant attorney general Kenneth A. Polite Jr. <a data-offer-url=\"https:\/\/www.justice.gov\/opa\/pr\/two-arrested-alleged-conspiracy-launder-45-billion-stolen-cryptocurrency\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.justice.gov\/opa\/pr\/two-arrested-alleged-conspiracy-launder-45-billion-stolen-cryptocurrency&quot;}\" href=\"https:\/\/www.justice.gov\/opa\/pr\/two-arrested-alleged-conspiracy-launder-45-billion-stolen-cryptocurrency\" rel=\"nofollow noopener\" target=\"_blank\">at the time<\/a>, \u201cToday, federal law enforcement demonstrates once again that we can follow money through the blockchain.\u201d<\/p>\n<p class=\"paywall\">Crypto wallets may be pseudonymous, but many exchanges have <a data-offer-url=\"https:\/\/www.fool.com\/the-ascent\/cryptocurrency\/articles\/what-is-kyc-and-why-do-crypto-exchanges-require-it\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.fool.com\/the-ascent\/cryptocurrency\/articles\/what-is-kyc-and-why-do-crypto-exchanges-require-it\/&quot;}\" href=\"https:\/\/www.fool.com\/the-ascent\/cryptocurrency\/articles\/what-is-kyc-and-why-do-crypto-exchanges-require-it\/\" rel=\"nofollow noopener\" target=\"_blank\">Know Your Customer protocols<\/a> and collect <a data-offer-url=\"https:\/\/www.coindesk.com\/layer2\/privacyweek\/2022\/01\/27\/before-you-click-i-agree-how-binance-coinbase-and-22-other-crypto-exchanges-handle-your-data\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.coindesk.com\/layer2\/privacyweek\/2022\/01\/27\/before-you-click-i-agree-how-binance-coinbase-and-22-other-crypto-exchanges-handle-your-data\/&quot;}\" href=\"https:\/\/www.coindesk.com\/layer2\/privacyweek\/2022\/01\/27\/before-you-click-i-agree-how-binance-coinbase-and-22-other-crypto-exchanges-handle-your-data\/\" rel=\"nofollow noopener\" target=\"_blank\">tons of other data on users<\/a>. Moreover, transactions necessarily require sharing your wallet with another party. As software engineer <a data-offer-url=\"https:\/\/blog.mollywhite.net\/abuse-and-harassment-on-the-blockchain\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/blog.mollywhite.net\/abuse-and-harassment-on-the-blockchain\/&quot;}\" href=\"https:\/\/blog.mollywhite.net\/abuse-and-harassment-on-the-blockchain\/\" rel=\"nofollow noopener\" target=\"_blank\">Molly White wrote<\/a>, once someone knows your wallet address, privacy can be difficult, if not impossible to maintain: \u201cImagine if, when you Venmoed your Tinder date for your half of the meal, they could now see every other transaction you\u2019d ever made\u2014and not just on Venmo, but the ones you made with your credit card, bank transfer, or other apps, and with no option to set the visibility of the transfer to \u2018private.\u2019\u201d<\/p>\n<p class=\"paywall\">The primary way to combat this public scrutiny is with <a data-offer-url=\"https:\/\/arxiv.org\/ftp\/arxiv\/papers\/1706\/1706.05432.pdf\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/arxiv.org\/ftp\/arxiv\/papers\/1706\/1706.05432.pdf&quot;}\" href=\"https:\/\/arxiv.org\/ftp\/arxiv\/papers\/1706\/1706.05432.pdf\" rel=\"nofollow noopener\" target=\"_blank\">obfuscation methods<\/a> like using unique wallets for each transaction, or employing <a data-offer-url=\"https:\/\/en.wikipedia.org\/wiki\/Cryptocurrency_tumbler\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/en.wikipedia.org\/wiki\/Cryptocurrency_tumbler&quot;}\" href=\"https:\/\/en.wikipedia.org\/wiki\/Cryptocurrency_tumbler\" rel=\"nofollow noopener\" target=\"_blank\">a tumbler or mixer service<\/a>. The latter combines many people&#x27;s money into one pool and then redistributes it so as to obscure which money is going where. While this process itself isn&#x27;t inherently illegal or even suspicious, you&#x27;d be forgiven for thinking it <a data-offer-url=\"https:\/\/youtu.be\/RhsUHDJ0BFM\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/youtu.be\/RhsUHDJ0BFM&quot;}\" href=\"https:\/\/youtu.be\/RhsUHDJ0BFM\" rel=\"nofollow noopener\" target=\"_blank\">sounds a bit like money laundering<\/a>, because sometimes it&#x27;s used for exactly that.<\/p>\n<p class=\"paywall\">These techniques <a href=\"https:\/\/www.wired.com\/story\/bitcoin-seizure-record-doj-crypto-tracing-monero\/\">are by no means foolproof<\/a>, but even if they were, it&#x27;s a cumbersome layer of work that simply doesn&#x27;t scale. An obsessed crypto investor with plenty of time on his hands might learn how to manage a dozen crypto wallets, a wallet manager, a mixer, and every other tool needed to stay anonymous. But that&#x27;s work the average person simply can&#x27;t be expected to do on their own.<\/p>\n<p class=\"paywall\">A key component to keeping crypto activity anonymous is to avoid tying transactions to any identifying information. Which means NFTs, by their nature, can fundamentally undermine this goal. The idea behind NFTs is that they are fundamentally unique, identifiable tokens. And while they <a href=\"https:\/\/www.wired.com\/story\/nfts-dont-work-the-way-you-think-they-do\/\">don&#x27;t work quite the way advocates say they do<\/a>, it&#x27;s still technically true that no individual NFT can be duplicated.<\/p>\n<p class=\"paywall\">This means that, if a user ties an NFT to any part of their online or IRL identity\u2014say by <a href=\"https:\/\/www.wired.com\/story\/nft-metaverse-facebook-twitter\/\">using an NFT as a profile picture on Twitter<\/a> or <a href=\"https:\/\/www.wired.com\/story\/opensea-nfts-twitter\/\">maintaining a profile on an NFT marketplace<\/a>\u2014it becomes trivially easy to find out what else their wallet has been up to.<\/p>\n<p class=\"paywall\">This doesn&#x27;t even require using a specific app or service. For example, when Jimmy Fallon <a data-offer-url=\"https:\/\/youtu.be\/5zi12wrh5So?t=306\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/youtu.be\/5zi12wrh5So?t=306&quot;}\" href=\"https:\/\/youtu.be\/5zi12wrh5So?t=306\" rel=\"nofollow noopener\" target=\"_blank\">showed off his Bored Ape on TV<\/a>, that made it very easy to find <a data-offer-url=\"https:\/\/etherscan.io\/address\/0x0394451c1238cec1e825229e692aa9e428c107d8\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/etherscan.io\/address\/0x0394451c1238cec1e825229e692aa9e428c107d8&quot;}\" href=\"https:\/\/etherscan.io\/address\/0x0394451c1238cec1e825229e692aa9e428c107d8\" rel=\"nofollow noopener\" target=\"_blank\">Jimmy Fallon\u2019s wallet<\/a> address and see <a data-offer-url=\"https:\/\/news.knowyourmeme.com\/news\/crypto-wallet-supposedly-belonging-to-jimmy-fallon-bought-trump-nft-and-lets-go-brandon-crypto-coins\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/news.knowyourmeme.com\/news\/crypto-wallet-supposedly-belonging-to-jimmy-fallon-bought-trump-nft-and-lets-go-brandon-crypto-coins&quot;}\" href=\"https:\/\/news.knowyourmeme.com\/news\/crypto-wallet-supposedly-belonging-to-jimmy-fallon-bought-trump-nft-and-lets-go-brandon-crypto-coins\" rel=\"nofollow noopener\" target=\"_blank\">what other transactions his wallet has been involved in<\/a>, including <a data-offer-url=\"https:\/\/etherscan.io\/tx\/0x494ae181ab85ffddb5c45a90e491faebd0e85275111652bbbf438eeafe285c91\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/etherscan.io\/tx\/0x494ae181ab85ffddb5c45a90e491faebd0e85275111652bbbf438eeafe285c91&quot;}\" href=\"https:\/\/etherscan.io\/tx\/0x494ae181ab85ffddb5c45a90e491faebd0e85275111652bbbf438eeafe285c91\" rel=\"nofollow noopener\" target=\"_blank\">a user sending him 1,776 Let&#x27;s Go Brandon tokens<\/a>.<\/p>\n<p class=\"paywall\">While knowing who bought which JPEG might not seem like a major deal, it becomes a critical issue as crypto advocates push the idea of using NFTs for <a data-offer-url=\"https:\/\/fortune.com\/2022\/02\/12\/nft-florida-home-sale-ether-crypto\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/fortune.com\/2022\/02\/12\/nft-florida-home-sale-ether-crypto\/&quot;}\" href=\"https:\/\/fortune.com\/2022\/02\/12\/nft-florida-home-sale-ether-crypto\/\" rel=\"nofollow noopener\" target=\"_blank\">home ownership<\/a>, <a data-offer-url=\"https:\/\/www.fastcompany.com\/90719028\/its-not-just-art-nfts-could-revolutionize-healthcare-bioethicists-say\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.fastcompany.com\/90719028\/its-not-just-art-nfts-could-revolutionize-healthcare-bioethicists-say&quot;}\" href=\"https:\/\/www.fastcompany.com\/90719028\/its-not-just-art-nfts-could-revolutionize-healthcare-bioethicists-say\" rel=\"nofollow noopener\" target=\"_blank\">medical records<\/a>, and <a data-offer-url=\"https:\/\/blockdotco.medium.com\/nfts-and-social-media-604e8d12ea4a\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/blockdotco.medium.com\/nfts-and-social-media-604e8d12ea4a&quot;}\" href=\"https:\/\/blockdotco.medium.com\/nfts-and-social-media-604e8d12ea4a\" rel=\"nofollow noopener\" target=\"_blank\">social media<\/a>. A single wallet\u2014or even a network of wallets that are not adequately obfuscated\u2014could act as a giant bucket of personal data that not only can&#x27;t be kept private, but can&#x27;t be deleted from the blockchain.<\/p>\n<p class=\"paywall\">Not only are transaction histories public for every wallet address on platforms like Ethereum\u2014the largest NFT platform today\u2014but it\u2019s possible to send NFTs to any address, regardless of whether the recipient approves the transaction. For example, in December 2021, rapper Waka Flocka Flame found a number of NFTs he hadn\u2019t purchased <a data-offer-url=\"https:\/\/twitter.com\/WakaFlocka\/status\/1475709903184412675\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/twitter.com\/WakaFlocka\/status\/1475709903184412675&quot;}\" href=\"https:\/\/twitter.com\/WakaFlocka\/status\/1475709903184412675\" rel=\"nofollow noopener\" target=\"_blank\">appearing in his wallet<\/a>.<\/p>\n<p class=\"paywall\">Since blockchains are immutable, append-only records of transactions, tokens dropped into a user\u2019s wallet can\u2019t just be deleted. Instead, they have to be \u201cburned.\u201d Burning is a type of transaction where an NFT (or any other token) is transferred to an address that no one owns and can\u2019t be accessed, effectively making it impossible to recover. This, of course, <a data-offer-url=\"https:\/\/nftexplained.info\/what-is-burning-an-nft-a-complete-guide-and-explanation\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/nftexplained.info\/what-is-burning-an-nft-a-complete-guide-and-explanation\/&quot;}\" href=\"https:\/\/nftexplained.info\/what-is-burning-an-nft-a-complete-guide-and-explanation\/\" rel=\"nofollow noopener\" target=\"_blank\">comes with transaction fees<\/a>.<\/p>\n<p class=\"paywall\">Removing anything from your wallet\u2014including spam, unsolicited dick pics, or harassing images <a data-offer-url=\"https:\/\/web3isgoinggreat.com\/?id=2022-02-07-4\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/web3isgoinggreat.com\/?id=2022-02-07-4&quot;}\" href=\"https:\/\/web3isgoinggreat.com\/?id=2022-02-07-4\" rel=\"nofollow noopener\" target=\"_blank\">or messages<\/a>\u2014can\u2019t be done without shelling out money. So, for example, if Jimmy Fallon wanted to get rid of those 1,776 Let\u2019s Go Brandon tokens (a transaction someone paid $30.25 worth of ETH to conduct), the only way to remove them is to pay a similar transaction fee to send the tokens somewhere else. And that fee applies per transaction.<\/p>\n<p class=\"paywall\">Moreover, NFTs aren\u2019t strictly limited to static links. Every NFT is governed by a \u201csmart contract.\u201d These contracts are essentially small containers for code that developers can build mini applets in. This is what enables things like royalty payments, but the code inside can be anything, including misleading scams or even malware.<\/p>\n<p class=\"paywall\">One <a href=\"https:\/\/www.wired.com\/story\/squid-game-coin-crypto-scam\/\">high-profile scam<\/a> involved a play-to-earn game modeled after Netflix\u2019s <em>Squid Game<\/em>. The project leaders sold Squid tokens, which rose by <a data-offer-url=\"https:\/\/www.washingtonpost.com\/world\/2021\/11\/02\/squid-game-crypto-rug-pull\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.washingtonpost.com\/world\/2021\/11\/02\/squid-game-crypto-rug-pull\/&quot;}\" href=\"https:\/\/www.washingtonpost.com\/world\/2021\/11\/02\/squid-game-crypto-rug-pull\/\" rel=\"nofollow noopener\" target=\"_blank\">nearly 23 <em>million<\/em> percent in less than a week<\/a>, but the smart contract forbade selling any Squid tokens without also burning a number of Marbles tokens, which players were meant to earn in the game. The project <a data-offer-url=\"https:\/\/www.reddit.com\/r\/CryptoScams\/comments\/ql5y6c\/psa_i_lost_everything_how_squid_game_token\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.reddit.com\/r\/CryptoScams\/comments\/ql5y6c\/psa_i_lost_everything_how_squid_game_token\/&quot;}\" href=\"https:\/\/www.reddit.com\/r\/CryptoScams\/comments\/ql5y6c\/psa_i_lost_everything_how_squid_game_token\/\" rel=\"nofollow noopener\" target=\"_blank\">collapsed after a week<\/a>, before the game even launched, and after the creators disappeared with the money, leaving the Squid tokens worthless.<\/p>\n<p class=\"paywall\">Since Marbles tokens can\u2019t be earned, users who bought the Squid tokens <a data-offer-url=\"https:\/\/blog.redeeem.com\/squid-game-tokens-cant-be-sold-by-investors\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/blog.redeeem.com\/squid-game-tokens-cant-be-sold-by-investors\/&quot;}\" href=\"https:\/\/blog.redeeem.com\/squid-game-tokens-cant-be-sold-by-investors\/\" rel=\"nofollow noopener\" target=\"_blank\">can\u2019t sell them<\/a>, even as a novelty. According to the rules of the smart contract that governs Squid tokens, they will likely remain in investors wallets forever.\u00a0<\/p>\n<p class=\"paywall\">The immutable nature of the blockchain also means that patching code is essentially impossible. The point of the system is to maintain an unchangeable, append-only record, so the only way to update smart contracts\u2014which again, are just code that is susceptible to human error and exploitation\u2014is to replace them entirely with a new contract and migrate old tokens to it.<\/p>\n<p class=\"paywall\">This happened recently with the Sandbox, a game world that sells <a href=\"https:\/\/www.wired.com\/story\/metaverse-land-rush-illusion\/\">NFTs of virtual land<\/a>. A vulnerability in the previous smart contract could\u2019ve made it possible for an attacker to <a data-offer-url=\"https:\/\/slowmist.medium.com\/the-vulnerability-behind-the-sandbox-land-migration-2abf68933170\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/slowmist.medium.com\/the-vulnerability-behind-the-sandbox-land-migration-2abf68933170&quot;}\" href=\"https:\/\/slowmist.medium.com\/the-vulnerability-behind-the-sandbox-land-migration-2abf68933170\" rel=\"nofollow noopener\" target=\"_blank\">burn another player\u2019s NFT without permission<\/a> from the owner. To resolve this, the Sandbox <a data-offer-url=\"https:\/\/medium.com\/sandbox-game\/the-sandbox-land-smart-contract-migration-4293d235f27f\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/medium.com\/sandbox-game\/the-sandbox-land-smart-contract-migration-4293d235f27f&quot;}\" href=\"https:\/\/medium.com\/sandbox-game\/the-sandbox-land-smart-contract-migration-4293d235f27f\" rel=\"nofollow noopener\" target=\"_blank\">issued a new smart contract<\/a> and directed users to migrate their land tokens.<\/p>\n<p class=\"paywall\">However, since every transaction on the Ethereum blockchain costs fees, someone has to pay for every part of this process. The Sandbox has offered to pay the gas fees for all of its users who must now migrate to a new smart contract, but not every project would be willing or able to do so.<\/p>\n<p class=\"paywall\">There are countless alternative crypto platforms and services that share some flaws with the most common platforms like Ethereum today. Some might be fixable, but for now the most common players and tools have critical flaws when it comes to basic privacy and security that have gone far too often overlooked.\u00a0<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/nfts-privacy-security-nightmare\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/624b7b34a288ab4bb7de3714\/master\/pass\/NFT-Privacy-Security-1317721353.jpg\"\/><\/p>\n<p><strong>Credit to Author: Eric Ravenscraft| Date: Tue, 05 Apr 2022 11:00:00 +0000<\/strong><\/p>\n<p>The blockchain isn\u2019t as \u201canonymous\u201d as you might think.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714,21382],"class_list":["post-18678","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security","tag-security-privacy"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18678","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=18678"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18678\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=18678"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=18678"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=18678"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}