MMashDiv

NFT Marketplace 6.3.3

Latest

1 October 2026

SECURITYPURCHASESMASTER WALLET

NFT Marketplace v6.3.3

Release Date: October 1, 2026 Tags: SECURITY, PURCHASES, MASTER WALLET

Overview

The buy route could spend the platform's own funds. For an item also listed on the on-chain marketplace contract, a purchase had the master wallet buy it through that contract: the master wallet paid the seller and received the NFT, while the buyer's payment had gone to the collection contract. The platform's own buy buttons never reached this — it took hand-made requests — and the route now always transfers the NFT directly from seller to buyer.

No new dependency: requires Core v6.7.6, as before.

Update Instructions

pnpm updator

No schema change, no seeder, no .env change.


Fixed

The buy route could spend the master wallet's funds

  • Fixed the buy route, for an item also listed on the on-chain marketplace contract, paying the seller from the master wallet and sending the NFT to the master wallet. Purchases now always transfer directly from seller to buyer, so an item a seller listed on the marketplace contract themselves, outside the platform, can no longer be bought through the platform: the purchase fails, the listing returns to sale, and the log carries a warning tagged NFT_PURCHASE beginning "Marketplace leg skipped for listing".