Site icon Nairametrics

Cyber thief steals NFTs worth million of dollars

Yahoo Yahoo

OpenSea, a leading marketplace for NFTs, is investigating the “rumors of an exploit” involving smart contracts connected to its platform following an outbreak of panicked tweets from traders who lost valuable tokens.

According to PeckShield, a blockchain security firm that audits smart contracts, the exploit is likely phishing, through which a malicious contract is hidden within a disguised link. One of the possible sources of the link was an email about the migration process sent to all employees.

In addition to the ETH held by the attacker’s address (slapped with a phish/hack warning badge by blockchain explorer Etherscan), ether worth $1.7 million, two Cool Cats, one Azuki, and three tokens from the Bored Ape Yacht Club.

An exploit involving smart contracts related to OpenSea is under investigation, according to a post on Twitter made by OpenSea Saturday night.

Read: Crypto: Why NFTs can bail Nigeria’s ailing Education Sector

“Apparently, an external website is behind the phishing attack. Links outside of opensea.io shouldn’t be clicked,” OpenSea said.

In a tweet later, OpenSea CEO, Devin Finzer reported that “32 users’ NFTs have been hacked after signing a malicious payload.”

Read: How NFTs can protect Nigeria’s cultural heritage

He added that the company was unaware of any recent phishing emails sent to users, and suggested that a fraudulent website could be responsible.

On Friday, OpenSea will release a brand-new smart contract to revamp its trading platform code (basically, the code that governs it). Old, inactive listings on the platform were eventually to be removed with the upgraded contract.

A trader posted an email he thought was from OpenSea regarding contract B migration.

https://twitter.com/ScottBussing/status/1495229984918540289

How to protect your NFTs       

Exit mobile version