Stock Groups

Hundreds of NFTs Stolen in OpenSea Phishing Attack -Breaking

[ad_1]

OpenSea Phishing Attack: Stolen Hundreds of NFTs

The world’s largest NFT marketplace, OpenSea, suffered a massive heist this weekend as 254 unique non-fungible tokens (NFTs) were stolen.

Twenty-two OpenSea wallets had their NFT assets stolen during an intrusion that later became a phishing attack. It is estimated that the total damages caused to those affected by this intrusion amount to $3 million.

Was it a mistake?

OpenSea users found their NFT wallets empty and lacking valuable assets on Saturday.

More than an hour after the losses were noticed, Opensea reported an ongoing investigation into what “appears to be a phishing attack originating outside of OpenSea’s website.”

Devin Finzer from OpenSea, CEO of OpenSea, quickly confirmed that the hack was caused by a phishing attack. The attacker had 32 users sign malicious payloads.

Later, it was discovered that the hacker had used an ordinary phishing email to mimic the OpenSea official mail from the previous day.

A malicious email was sent to users urging them to transfer their tokens into the new smart contract before Friday 25 February, or else all tokens would be lost.

OpenSea’s smart contract was announced by the company a day earlier to get rid of inactive NFT lists from its platform. OpenSea users needed to migrate their NFT listings that had expired to another smart contract after the upgrade. It was meant to be difficult for malicious actors to fool users into signing contracts without their knowledge.

The Ethereum network was the dominant platform for OpenSea transactions by 2021 (97%) There is currently cross-blockchain support available on the popular marketplace, which includes Ethereum, Polygon, and Klaytn Blockchains.

OpenSea’s CTO Nadav Hollander later commented that none of the malicious orders originated from OpenSea’s website, nor from the official company’s emails. According to him, the orders were unrelated to OpenSea’s migration flow.

Thus, the hacker exploited victims by convincing them to visit an imposter site. There they signed orders to move their NFTs to OpenSea. Instead of secure transfers though, users sent their NFTs to the hacker’s wallet, allowing the bad actors to take control of nearly $3 million worth of non-fungible tokens.

OpenSea then reported that the attacker was still active after a few hours. However, no malicious activity has been found since.

The world’s largest NFT marketplace promised that it would continue its investigation and keep users updated. OpenSea confirmed that 17 victims were identified as of Monday 21st. This is in contrast to 32 previously reported.

OpenSea customers continue to report NFT wallet drains and point fingers at the platform for denial of an attack and minimization of a problem.

It’s not the first time

This isn’t the first instance of malicious actors exploiting OpenSea users to commit a phishing attack.

As recently as January 2022, attackers exploited a vulnerability in the world’s largest NFT platform by accessing old NFT listings, buying them for old prices, and then reselling them for their contemporary price, which generated an instant profit of around 332 ETH ($800,000 USD).

EMAIL NEWSLETTER

Get the other side of crypto!

Upgrade your inbox and get our DailyCoin editors’ picks 1x a week delivered straight to your inbox.

[contact-form-7]
With just one click, you can unsubscribe at any time.

Continue reading on DailyCoin

[ad_2]