Around US$1.7million worth of non-fungible tokens were stolen from users on NFT marketplace OpenSea after a phishing attack on Saturday netted the hacker some 250 tokens from 17 people.
OpenSea CTO Nadav Hollander shared a rundown of what happened on Twitter, detailing that the affected users did sign a “malicious order.” This payload authorized the transfer of the NFT to the hacker for free.
- All of the malicious orders contain valid signatures from the affected users, indicating that they did sign an order somewhere, at some point in time. However, none of these orders were broadcasted to OpenSea at the time of signing.
CNET notes that it’s common for phishing to happen via emails, but in this case, it wasn’t through an email and it’s unknown how the users were duped. No suspicious links were clicked either, the victims reported.
Devin Finzer, CEO of OpenSea, shared that the hacker had US$1.7 million in his wallet after selling some of the stolen NFTs; however, they had also returned other tokens to their rightful owners.
This attack took place while OpenSea is in the middle of migrating to the new Wyvern smart contract system, which began on Friday, a day before the attack.
But ââHollander states the theft was “unlikely to be related to OpenSea’s migration flow” as the scam orders had been signed before the migration was carried out.
The marketplacehas just posted an update detailing that the attacker seems to no longer be active, and the wallet has been dormant for the last 36 hours. Investigations are continuing.
We ruled out our contract migration tool as a vector for the attack. It is safe to migrate your listings. For the technically inclined, check out this thread on how our new signature flow (used with any new listings) is a major improvement for user safetyhttps://t.co/t2597bRmIB