Millions of dollars worth of NFTs stolen from OpenSea users

Phishing attack saw victims essentially hand over blank check

Anthony Cuthbertson
Monday 21 February 2022 16:34 GMT
Comments
Demand for investment in art has surged through new technologies like NFTs.
Demand for investment in art has surged through new technologies like NFTs. (AFP via Getty Images)

Your support helps us to tell the story

From reproductive rights to climate change to Big Tech, The Independent is on the ground when the story is developing. Whether it's investigating the financials of Elon Musk's pro-Trump PAC or producing our latest documentary, 'The A Word', which shines a light on the American women fighting for reproductive rights, we know how important it is to parse out the facts from the messaging.

At such a critical moment in US history, we need reporters on the ground. Your donation allows us to keep sending journalists to speak to both sides of the story.

The Independent is trusted by Americans across the entire political spectrum. And unlike many other quality news outlets, we choose not to lock Americans out of our reporting and analysis with paywalls. We believe quality journalism should be available to everyone, paid for by those who can afford it.

Your support makes all the difference.

Dozens of NFT owners have lost $1.7 million worth of digital art in after being tricked in a cyber scam.

Users of the online NFT platform OpenSea were targeted by criminals, who used a technique known as phishing to get the owners to sign over the digital assets.

Blockchain security firm PeckShield recorded 253 tokens stolen during a three-hour period on Saturday evening, impacting 32 different OpenSea users.

Among the NFTs stolen were tokens from metaverse marketplace Decentraland and Bored Ape Yacht Club.

The phishing attack appears to have exploited a smart contract standard known as the Wyvern Protocol, which saw victims essentially sign a blank check for the attackers.

Phishing is one of the oldest forms of cyber attacks, though security experts have warned that they are constantly evolving and becoming increasingly sophisticated.

“Criminals are getting smarter and can still gain results from older, proven attack vectors,” David Mahdi, chief security officer at cyber security firm Sectigo, told The Independent.

“In the case of a phishing attack, it is no longer enough to watch out for crudely worded emails – recipients must also consider context, content and sender, particularly if financial transactions are involved.”

OpenSea is still investigating the attack, though has denied that its platform was compromised at any time.

“The attack did not originate on opensea.io,” tweeted Devin Finzer, CEO and co-founder of the NFT platform.

“We’re actively working with users whose items were stolen to narrow down a set of common websites that they interacted with that might have been responsible for the malicious signatures.”

Join our commenting forum

Join thought-provoking conversations, follow other Independent readers and see their replies

Comments

Thank you for registering

Please refresh the page or navigate to another page on the site to be automatically logged inPlease refresh your browser to be logged in