OpenSea Phishing Attack: $1.7 Million In NFTs Stolen
Unfortunately, the weekend passed with some very disappointing news coming from the platform OpenSea. According to the reports, on Saturday, it seems that attackers stole hundreds of NFTs from OpenSea users, causing a la...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Unfortunately, the weekend passed with some very disappointing news coming from the platform OpenSea.
According to the reports, on Saturday, it seems that attackers stole hundreds of NFTs from OpenSea users, causing a late-night panic among the site’s broad user base.
254 tokens were stolenIt’s been reported that a spreadsheet compiled by the blockchain security service PeckShield counted 254 tokens stolen over the course of the attack.
It’s also important to note that this included tokens from Decentraland and Bored Ape Yacht Club.
The Verge online publication notes that the bulk of the attacks took place between 5 PM and 8 PM ET, and it targeted 32 users in total.
Molly White, who runs the blog Web3 is Going Great, estimated the value of the stolen tokens at more than $1.7 million.
The Verge notes the following:
“The attack appears to have exploited a flexibility in the Wyvern Protocol, the open-source standard underlying most NFT smart contracts, including those made on OpenSea.”
It’s been also reported that one explanation (linked by CEO Devin Finzer on Twitter) described the attack in two parts:
“first, targets signed a partial contract, with a general authorization and large portions left blank. With the signature in place, attackers completed the contract with a call to their own contract, which transferred ownership of the NFTs without payment.”
One of the largest signature phishing attacks just happened.
Here’s a 🧵 on how to avoid getting hacked by signature attacks 👇
— Treasure Seeker (@treasuresETH) February 20, 2022
According to the same reports, all in all, the targets of the attack had signed a blank check, and once it was signed, attackers filled in the rest of the check to take their holdings.
“I checked every transaction,” said the user, who goes by Neso.
The user continued:
“They all have valid signatures from the people who lost NFTs so anyone claiming they didn’t get phished but lost NFTs is sadly wrong.”
Check out more details in the original post.
The post OpenSea Phishing Attack: $1.7 Million In NFTs Stolen first appeared on CryptoGazette - Cryptocurrency News.Why this matters
This security story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on CryptoGazetteRelated market context
Bitcoin purchases halted after data breach puts 250,000 crypto users at risk
Israel’s largest regulated cryptocurrency broker, Bits of Gold, is investigating a data breach that potentially exposed the person...
Over 1.3 million staked tokens remain stranded onchain after a major validator missed its deadline to exit Aztec
DV Labs’ planned Aug. 15 Aztec exit was still incomplete by 2 a.m. UTC on Aug. 16: seven DV Labs-listed attesters remained in the...
OpenSea founder pivoted to AI — and won
OpenSea, once one of the most prominent companies in the cryptocurrency industry, has slowly been bleeding users and relevancy ove...
Bits of Gold Breach May Expose 200,000 Crypto Users, But Funds Remain Safe Online
Key Takeaways: A data breach at Bits of Gold could affect up to 200,000 customers. No exposure of customer funds, crypto assets, p...
SafePal Bitcoin Wallet Data Breach Stokes Fears of Physical Attacks
A flaw in an order-tracking plug-in of bitcoin wallet provider SafePal exposed names, addresses and phone numbers of nearly 40,000...
Record user activity and a collapse in whale selling should send XRP soaring, so why is it still pinned at $1?
XRP is back near $1 even as network activity rebounds, whale deposits to Binance collapse, and derivatives exposure builds near re...