OpenSea Phishing Attack: $1.7 Million In NFTs Stolen
Unfortunately, the weekend passed with some very disappointing news coming from the platform OpenSea. According to the reports, on Saturday, it seems that attackers stole hundreds of NFTs from OpenSea users, causing a la...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Unfortunately, the weekend passed with some very disappointing news coming from the platform OpenSea.
According to the reports, on Saturday, it seems that attackers stole hundreds of NFTs from OpenSea users, causing a late-night panic among the site’s broad user base.
254 tokens were stolenIt’s been reported that a spreadsheet compiled by the blockchain security service PeckShield counted 254 tokens stolen over the course of the attack.
It’s also important to note that this included tokens from Decentraland and Bored Ape Yacht Club.
The Verge online publication notes that the bulk of the attacks took place between 5 PM and 8 PM ET, and it targeted 32 users in total.
Molly White, who runs the blog Web3 is Going Great, estimated the value of the stolen tokens at more than $1.7 million.
The Verge notes the following:
“The attack appears to have exploited a flexibility in the Wyvern Protocol, the open-source standard underlying most NFT smart contracts, including those made on OpenSea.”
It’s been also reported that one explanation (linked by CEO Devin Finzer on Twitter) described the attack in two parts:
“first, targets signed a partial contract, with a general authorization and large portions left blank. With the signature in place, attackers completed the contract with a call to their own contract, which transferred ownership of the NFTs without payment.”
One of the largest signature phishing attacks just happened.
Here’s a 🧵 on how to avoid getting hacked by signature attacks 👇
— Treasure Seeker (@treasuresETH) February 20, 2022
According to the same reports, all in all, the targets of the attack had signed a blank check, and once it was signed, attackers filled in the rest of the check to take their holdings.
“I checked every transaction,” said the user, who goes by Neso.
The user continued:
“They all have valid signatures from the people who lost NFTs so anyone claiming they didn’t get phished but lost NFTs is sadly wrong.”
Check out more details in the original post.
The post OpenSea Phishing Attack: $1.7 Million In NFTs Stolen first appeared on CryptoGazette - Cryptocurrency News.Why this matters
This security story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on CryptoGazetteRelated market context
Europol warns crypto wallets are the weak spot for future quantum attacks
The crypto industry must urgently adopt quantum-resistant cryptography to prevent future vulnerabilities and secure digital assets...
Polymarket’s upgrade won’t automatically move existing bets to new contracts
Polymarket’s Protocol V2 rollout does not automatically move existing bets held under its older Conditional Tokens Framework, or C...
S&P brings ratings-style scrutiny to $10 billion crypto vault market as $6 million Base incident exposes risks
S&P Global is bringing ratings-style risk assessments to crypto lending vaults as the fast-growing market confronts fresh security...
Ethereum Tests 200 Million Gas Limit On Sepolia As Glamsterdam Moves Forward
TL;DR: Ethereum’s Sepolia testnet is testing a 200 million block gas limit as part of work around the Glamsterdam upgrade. The exp...
Tether Celebrates 12 Years, USD₮ Surpasses 700M Users
Key Takeaways: Tether marked the 12th anniversary of the world’s largest stablecoin by market cap, USD₮. The company claims that U...
Robinhood Puts $25 Million of Bitcoin on Its Balance Sheet, Executive Says
Robinhood has added $25 million worth of bitcoin to its balance sheet. Johann Kerbrat, a senior vice president who is also general...