30 Common Mistakes NFT Developers Make (And How to Avoid Them)
NFT development combines smart contract security with art, metadata, and launch logistics. Here are the most common mistakes that cost NFT developers money, reputation, or both.
Smart Contract Vulnerabilities
Using sequential token IDs for reveal
Predictable token IDs let snipers identify rare NFTs before reveal by watching metadata.
No reentrancy protection on mint
Mint functions with callbacks (like safe transfers) can be exploited for extra mints.
Integer overflow in batch minting
Pre-0.8.0 contracts without SafeMath could overflow mint counters.
Unchecked array lengths in airdrops
Airdrop functions without length limits can exceed block gas limit.
Allowing mints to contracts without callback check
Minting to non-ERC721Receiver contracts locks tokens permanently.
Allowlist Issues
Storing allowlist on-chain
On-chain arrays are expensive and can be manipulated by watching transactions.
No per-wallet mint limits on allowlist
Allowlisted addresses can transfer their spot to others or mint multiple times.
Merkle proof replay attacks
Valid proofs can be reused if contract doesn't track used proofs.
Allowlist signature without expiry
Signed allowlist entries without expiry can be used indefinitely.
Front-runnable signature reveals
Signatures revealed in pending transactions can be stolen.
Metadata Problems
Centralized metadata hosting
Traditional hosting means metadata disappears if server goes down.
Mutable metadata without transparency
Ability to change metadata after mint destroys trust.
No provenance hash
Without provenance, you cannot prove art was finalized before minting.
Incorrect token URI implementation
Returning wrong URI format breaks marketplace display.
Large image files
Large files slow loading and increase IPFS pinning costs.
Randomness Failures
Using block.timestamp for randomness
Miners can manipulate timestamps within bounds. Not truly random.
Predictable blockhash randomness
blockhash(block.number) is always 0. blockhash of past blocks can be known.
Single-transaction reveal
Reveals in same transaction as mint let attackers simulate and cherry-pick.
Insufficient randomness entropy
Combining weak entropy sources doesn't make strong randomness.
Access Control
Owner can rug-pull funds
Arbitrary withdrawal functions let owners steal mint proceeds.
No withdrawal function
Forgetting to include a withdrawal function locks ETH in contract forever.
Single owner key
One compromised key loses entire collection control.
Pausable without unpause
Some contracts can be paused but have no unpause function.
Royalty Issues
No on-chain royalty support
Without EIP-2981, royalties depend on marketplace voluntary enforcement.
Immutable royalty recipient
Cannot update royalty address if wallet is compromised.
Excessive royalty percentages
Very high royalties encourage marketplace bypass.
Launch Mistakes
No gas optimization
High gas costs during popular mints price out regular users.
Unverified contract on Etherscan
Unverified contracts look suspicious and reduce trust.
No testnet testing
Deploying directly to mainnet without thorough testing.
Wrong network deployment
Accidentally deploying to wrong network or testnet with real funds.
Key Recommendations
Deploy a test collection first. Iterate on metadata and minting before the real launch.
Gas optimization matters for minting. Users will compare your mint cost to competitors.
Test with large collection sizes. Bugs often appear at scale.
