21/02/2022 $1.7 million in NFTs stolen in apparent phishing attack on OpenSea users

Two hundred and fifty-four tokens were stolen over roughly three hours

Illustration by Alex Castro / The Verge

On Saturday, attackers stole hundreds of NFTs from OpenSea users, causing a late-night panic among the site’s broad user base.A spreadsheet compiled by the blockchain security service PeckShield counted 254 tokens stolen over the course of the attack, including tokens from Decentraland and Bored Ape Yacht Club.

The bulk of the attacks took place between 5PM and 8PM ET, targeting 32 users in total. Molly White, who runs the blog Web3 is Going Great, estimated the value of the stolen tokens at more than $1.7 million.

“They all have valid signatures”

The attack appears to have exploited a flexibility inthe Wyvern Protocol, the open-source standard underlying most NFT smart contracts, including those made on OpenSea. One explanation (linked by CEO Devin Finzeron Twitter) described the attack in two parts: first, targets signed a partial contract, with a general authorization and large portions left blank. With the signature in place, attackers completed the contract with a call to their own contract, which transferred ownership of the NFTs without payment. In essence, targets of the attack had signed a blank check — and once it was signed, attackers filled in the rest of the check to take their holdings.

“I checked every transaction,” saidthe user, who goes by Neso. “They all have valid signatures from the people who lost NFTs so anyone claiming they didn’t get phished but lost NFTs is sadly wrong.”

Valued at $13 billion in a recent funding round, OpenSea has becomeone of the most valuable companies of the NFT boom, providing a simple interface for users to list, browse, and bid on tokens without interacting directly with the blockchain. That success has come with significant security issues, as the company has struggled with attacks that leveragedold contractsorpoisoned tokensto steal users’ valuable holdings.

OpenSea was in the process of updating its contract system when the attack took place, but OpenSea has denied that the attack originated with the new contracts. The relatively small number of targets makes such a vulnerability unlikely, since any flaw in the broader platform would likely be exploited on a far greater scale.

Still, many details of the attack remain unclear — particularly the method attackers used to get targets to sign the half-empty contract. Writing on Twitter shortly before 3AM ET, OpenSea CEO Devin Finzer said the attacks had not originated fromOpenSea’s website,its various listing systems, orany emails from the company. The rapid pace of the attack — hundreds of transactions in a matter of hours — suggests some common vector of attack, but so far no link has been discovered.

“We’ll keep you updated as we learn more about the exact nature of the phishing attack,” said Finzer on Twitter. “If you have specific information that could be useful, please DM@opensea_support.”

Arts

https://www.theverge.com/2022/2/20/22943228/opensea-phishing-hack-smart-contract-bug-stolen-nft

Interesting NFTs
Crypto Toy Coin
This piece represents the creation of a new "Visual Toy", a term created by me to encompass my unique and exclusive GIF-Arts. The latter, "Crypto Toy Coin" is the only and first in the cryptocurrency theme. In it I represent the fast-paced world of finance in the virtual environment, the Internet with its universe of colors and infinite visual impact, an optimistic and exciting future, a world of possibilities that opens before us. These "Visual Toys" invite you to imagine, that is their function, that is the game. The ultimate goal is that you imagine, that it is you who gives it meaning. There are no good or bad answers, just the projection of each one. I've only created the trigger, the piece where you can project your imagination and let it fly.
AI Huascaq #3/5
Transdimensional art is a movement of blending online and offline stylesassisted blending and combining different styles of online and offline art. AI Huasca uses a DMT style AI blending over a kaleidoscopic remix of a painting that was "generated" via acrylic paint after an entheogenic trip.
Elk Recessive Wild 7[2]c[3]
Good day! I'm Elk Recessive Wild 7[2]c[3]. I'm a professional Aerobics Athlete and I love chocolate. When no one's home, I invite my pals over and we listen to Frank Sinatra. Maybe you and I can be partners in crime.
#64878
By OthersideDeployer
Mars House
Mars House is the first NFT digital house in the world. Upon purchase of Mars House NFT, 3D files will be sent to the new owner by Krista Kim Studio Inc. for file upload to the owner’s Metaverse. Technical support for Mars House integration on Metaverse is provided. (Architectural Digest, March 14, 2021) “Kim ventured into NFTs while exploring meditative design during quarantine; her hope was to use the influx of digital life as an opportunity to promote wellbeing. Comprised entirely of light, the visual effects of her crypto-home are meant to omit a zen, healing atmosphere. The artist also partnered with musician Jeff Schroeder of The Smashing Pumpkins to create a calming musical accompaniment. So what makes the file a compelling purchase? Beyond the promise of buying into the lucrative NFT market, the home and all of the furniture in it can be built in real life by glass furniture-makers in Italy, as well as through MicroLED screen technology. Kim also has a strong visions the art being projected, as well. “Everyone should install an LED wall in their house for NFT art.” says the artist. “ This is the future, and Mars House demonstrates the beauty of that possibility.” The owner is in agreement to the following terms and conditions upon purchase of Mars House (hereby referred to as Mars House NFT): The collector agrees to own one copy of Mars House NFT on a single Metaverse platform. The collector is required to register Mars House NFT ownership with Krista Kim Studio Inc. Krista Kim Studio Inc. will provide technical support to upload and integrate Mars House NFT on a Metaverse platform. If/when Mars House is resold, the collector is required to delete all Mars House NFT 3D file(s) from his/her Metaverse, and provide verification of deletion to Krista Kim Studio Inc. before new 3D files are transferred to the new owner by the artist. The new owner is required to register Mars House NFT ownership with Krista Kim Studio Inc. Krista Kim Studio will send Mars House NFT 3D files directly to the new owner and provide support for Metaverse integration. This verified ownership transfer system will be appointed to Krista Kim Studio Inc. trusteeship, after 40 years of the date of the sale. Krista Kim Studio Inc. retains ownership of Mars House NFT copyright. All rights reserved. All reproductions of Mars House (NFT) in both digital and physical formats, are restricted. Mars House NFT physical furniture pieces, made of tempered printed glass in Italy, may be commissioned by the collector as NFT physical pieces.