Stealing STX with a Dragon
On Dec 13th, there were two suspicous contracts deployed that interacted with the byzantion marketplace v5 ✎ contract and was named as stacks-art-market: bad actor 1 ✎ , bad actor 2 ✎ .
It turned out that the two contracts together could extract 1644 STX from the escrow of open bids that were not placed by the attacker.
A new version of byzantion marketplace has been deployed since that prevents these exploits. Read more about the byzantion marketplace protocol.