Another abandoned governance is under attack - this time it's Rarible's.
@rarible was a well-known NFT marketplace between 2020 and 2022. It moved millions of dollars during the NFT frenzy. The protocol and its treasury are governed by
$veRARI holders - locked
$RARI - using veNomics to set voting power in the DAO, just like Curve does.
On September 20, a wallet bought 3.5 ETH worth of
$RARI and locked it in Rarible's contracts, receiving 132,576 veRARI in voting power.
Moments later, the same wallet submitted a proposal from a supposed activist investor called Falcon. According to the proposal text, they would "unlock veRARI's value for its holders."
In practice, if approved, the proposal transfers ownership of all contracts to "Falcon." The voting period ends on September 25 at 08:53 UTC.
Rarible DAO has a Security Council, so it is able to block the attack, if it manages to get the multisig signers who control the Council to act in time.
The strangest part of this attack is that Rarible has only $368 in its treasury, yet the attackers spent $9,311 to capture its governance.
Like other attacks, they don't want money - they want control over what Rarible can do, such as:
- The ability to mint unlimited
$RARI tokens on the market and sell them on the secondary market (while shorting it on an exchange)
- Stealing users' funds via
$WETH,
$USDC, and other token approvals (including NFTs) granted to Rarible's marketplace
- Draining all the tokens locked in the veRARI contract
These are just simple possibilities that let attackers extract profit without needing a treasury to steal from.
Over time, these attacks are getting more sophisticated, and the pool of potential victims keeps growing - even projects with no money worth stealing.
We recommend that anyone holding an address with approvals granted to Rarible revoke them, to avoid any trouble in case governance is indeed captured.