metaplex-foundation / metaplex

A directory of what the Metaplex Foundation works on!
https://metaplex.com
Apache License 2.0
3.32k stars 6.26k forks source link

Creating NFT collection with symbol of existing SPL token should be prohibited #868

Closed wimdows-nl closed 2 years ago

wimdows-nl commented 2 years ago

Describe the bug Currently, it looks like any malicious actor can create an NFT collection and use the symbol of an existing SPL token to hijack the Solana Explorer view or Solscan view.

It might be in combination with a revoked owner (null) on the original SPL token.

See our messed up SPL token here:

https://explorer.solana.com/address/8ymi88q5DtmdNTn2sPRNFkvMkszMHuLJ1e3RVdWjPa3s

Screen grab:

Untitled

The meta data that comes back in Solana Explorer looks like this:

meta

This clearly messes up the existing SPL token that was there and causes issues when people verify the contract address and other SPL token details.

Solution: Prevent NFT collections to have a an NFT code/symbol that already exists in the SPL token list.

github-actions[bot] commented 2 years ago

This Issue has received no activity for 30 days. We will close it in 2 days, please reopen if you are still experiencing this issue.

scara89 commented 1 year ago

Hi Wim ! Seems this issue is an other. According to @aheckmann , they did a massive update that may broke your token Check that comment related with this update authority adress: https://github.com/metaplex-foundation/metaplex/issues/1055#issuecomment-985838251

AqH29mZfQFgRpfwaPoTMWSKJ5kqauoc1FwVBRksZyQrt