

Phishing Attack Tricks 32 OpenSea Users Out of 254 NFTs
source link: https://news.slashdot.org/story/22/02/20/1951229/phishing-attack-tricks-32-opensea-users-out-of-254-nfts
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

Phishing Attack Tricks 32 OpenSea Users Out of 254 NFTs (theverge.com) 25
Posted by EditorDavid
on Sunday February 20, 2022 @03:34PM from the borrowed-apes dept.
"A spreadsheet compiled by the blockchain security service PeckShield counted 254 tokens stolen over the course of the attack, including tokens from Decentraland and Bored Ape Yacht Club." The bulk of the attacks took place between 5PM and 8PM ET, targeting 32 users in total. Molly White, who runs the blog Web3 is Going Great, estimated the value of the stolen tokens at more than $1.7 million.
The attack appears to have exploited a flexibility in the Wyvern Protocol, the open-source standard underlying most NFT smart contracts, including those made on OpenSea. One explanation (linked by CEO Devin Finzer on Twitter) described the attack in two parts: first, targets signed a partial contract, with a general authorization and large portions left blank. With the signature in place, attackers completed the contract with a call to their own contract, which transferred ownership of the NFTs without payment. In essence, targets of the attack had signed a blank check — and once it was signed, attackers filled in the rest of the check to take their holdings.
"I checked every transaction," said the user, who goes by Neso. "They all have valid signatures from the people who lost NFTs so anyone claiming they didn't get phished but lost NFTs is sadly wrong...."
Writing on Twitter shortly before 3AM ET, OpenSea CEO Devin Finzer said the attacks had not originated from OpenSea's website, its various listing systems, or any emails from the company. The rapid pace of the attack — hundreds of transactions in a matter of hours — suggests some common vector of attack, but so far no link has been discovered.
An update to OpenSea's smart contract was scheduled the day before (to remove old and inactive listings from the platform), and the scammer mimicked a genuine OpenSea email, according to The Street. A user who posted the text of the phishing email online explains that the scammer "then got a number of people to sign permissions with WyvernExchange. No exploit, just people not reading sign permissions as normal."
CEO Finzer told Bloomberg that some of the stolen NFTs have actually been returned, with no further malicious activity seen from the attacker's account. "He also dispelled rumors of a $200 million hack, saying the attacker has $1.7 million of Ethereum in his wallet from selling some of the stolen NFTs."
And PC Magazine shares this update about the wallet: CoinDesk reports that Etherscan, which bills itself as "the Ethereum blockchain explorer," has flagged the account that appears to be connected to these NFT thefts. (The public name of which is, fittingly enough, "Fake_Phishing5169.")
Recommend
-
4
Feature How to prepare for an effective phishing attack simulation Here's what users need to know about phishing attacks before you send out a test email....
-
8
Crypto wallet warns of iCloud phishing attack that led to $650K in stolen assets
-
7
Phishing attack pop-up targets MetaMask users visiting popular crypto sites
-
7
Bored Ape Yacht Club Discord compromised in $357,000 NFT phishing attackIgor Bonifacic·Weekend Editor
-
9
Apple’s macOS is more secure than other operating systems like Windows. But an increasing number of phishing and malware attacks now target Mac users. And, no matter how secure macOS is, it does not make Mac users immune from the danger of...
-
5
Report: 47% of orgs experienced a voice phishing attack last year
-
9
Phishing attack results in data breach at Pittsburgh-based health system
-
2
Signal phone numbers of 1,900 users exposed in Twilio phishing attack...
-
9
1,900 Signal users’ data have been compromised to a phishing attack August 18, 2022 ...
-
8
Steam users warned of sophisticated browser-in-the-browser phishing attack A lot more convincing than a phishing email By
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK