Don't miss the latest stories
Advertise Newsletter
Network
  • The Creative Finder
  • The Bazaar
  • Deals
  • Status Is Down
Community
  • Sign up / Log in
  • Discussion Forums
  • Calendar of Events
NEW

Follow

Share this

NFT
Crypto
Cybersecurity
Disputes
  • Disputes
MENU
  • Advertise with us
  • Submit tip/feedback
  • Work with us
  • Subscribe to newsletter
  • Subscribe to RSS
Advertise here
Advertisement

$1.7 Million Worth Of NFTs Stolen From Users In OpenSea Phishing Attack

By Ell Ko, 22 Feb 2022

Subscribe to newsletter
Like us on Facebook
Image ID 218574632 © Sedovukr | Dreamstime.com

 

Around US$1.7 million worth of non-fungible tokens were stolen from users on NFT marketplace OpenSea after a phishing attack on Saturday netted the hacker some 250 tokens from 17 people. 


OpenSea CTO Nadav Hollander shared a rundown of what happened on Twitter, detailing that the affected users did sign a “malicious order.” This payload authorized the transfer of the NFT to the hacker for free.

 

- All of the malicious orders contain valid signatures from the affected users, indicating that they did sign an order somewhere, at some point in time. However, none of these orders were broadcasted to OpenSea at the time of signing.

— Nadav Hollander (@NadavAHollander) February 20, 2022


CNET notes that it’s common for phishing to happen via emails, but in this case, it wasn’t through an email and it’s unknown how the users were duped. No suspicious links were clicked either, the victims reported.


Devin Finzer, CEO of OpenSea, shared that the hacker had US$1.7 million in his wallet after selling some of the stolen NFTs; however, they had also returned other tokens to their rightful owners. 

Advertisement
Advertisement


This attack took place while OpenSea is in the middle of migrating to the new Wyvern smart contract system, which began on Friday, a day before the attack. 

 

But ​​Hollander states the theft was “unlikely to be related to OpenSea’s migration flow” as the scam orders had been signed before the migration was carried out.


The marketplace has just posted an update detailing that the attacker seems to no longer be active, and the wallet has been dormant for the last 36 hours. Investigations are continuing.

 

We ruled out our contract migration tool as a vector for the attack. It is safe to migrate your listings. For the technically inclined, check out this thread on how our new signature flow (used with any new listings) is a major improvement for user safetyhttps://t.co/t2597bRmIB

— OpenSea (@opensea) February 22, 2022

 

 

 

[via Gizmodo and CNET, image ID 218574632 © Sedovukr | Dreamstime.com]

Receive interesting stories like this one in your inbox
Advertise here

More related news

Advertise here
Also check out these recent news
Web Design
Link to news page

When Your Website Goes Down, This Is the Page Customers Meet Instead

2027
Link to news page

2027 Already Has A Color Of The Year And It’s Beginning On ‘Grounded’ Territory

IKEA
Link to news page

IKEA & Xbox Press Play On Furniture & Storage Inspired By The Iconic Controller

Fashion
Link to news page

Vogue Presents ‘United Flags of Fashion’ With Top Designers For All 50 States

Coca-Cola
Link to news page

Coca-Cola Pours Fresh Life Into Its Iconic Branding With Worldwide Redesign