21/02/2022 $1.7 million in NFTs stolen in apparent phishing attack on OpenSea users

Two hundred and fifty-four tokens were stolen over roughly three hours

Illustration by Alex Castro / The Verge

On Saturday, attackers stole hundreds of NFTs from OpenSea users, causing a late-night panic among the site’s broad user base.A spreadsheet compiled by the blockchain security service PeckShield counted 254 tokens stolen over the course of the attack, including tokens from Decentraland and Bored Ape Yacht Club.

The bulk of the attacks took place between 5PM and 8PM ET, targeting 32 users in total. Molly White, who runs the blog Web3 is Going Great, estimated the value of the stolen tokens at more than $1.7 million.

“They all have valid signatures”

The attack appears to have exploited a flexibility inthe Wyvern Protocol, the open-source standard underlying most NFT smart contracts, including those made on OpenSea. One explanation (linked by CEO Devin Finzeron Twitter) described the attack in two parts: first, targets signed a partial contract, with a general authorization and large portions left blank. With the signature in place, attackers completed the contract with a call to their own contract, which transferred ownership of the NFTs without payment. In essence, targets of the attack had signed a blank check — and once it was signed, attackers filled in the rest of the check to take their holdings.

“I checked every transaction,” saidthe user, who goes by Neso. “They all have valid signatures from the people who lost NFTs so anyone claiming they didn’t get phished but lost NFTs is sadly wrong.”

Valued at $13 billion in a recent funding round, OpenSea has becomeone of the most valuable companies of the NFT boom, providing a simple interface for users to list, browse, and bid on tokens without interacting directly with the blockchain. That success has come with significant security issues, as the company has struggled with attacks that leveragedold contractsorpoisoned tokensto steal users’ valuable holdings.

OpenSea was in the process of updating its contract system when the attack took place, but OpenSea has denied that the attack originated with the new contracts. The relatively small number of targets makes such a vulnerability unlikely, since any flaw in the broader platform would likely be exploited on a far greater scale.

Still, many details of the attack remain unclear — particularly the method attackers used to get targets to sign the half-empty contract. Writing on Twitter shortly before 3AM ET, OpenSea CEO Devin Finzer said the attacks had not originated fromOpenSea’s website,its various listing systems, orany emails from the company. The rapid pace of the attack — hundreds of transactions in a matter of hours — suggests some common vector of attack, but so far no link has been discovered.

“We’ll keep you updated as we learn more about the exact nature of the phishing attack,” said Finzer on Twitter. “If you have specific information that could be useful, please DM@opensea_support.”

Arts

https://www.theverge.com/2022/2/20/22943228/opensea-phishing-hack-smart-contract-bug-stolen-nft

Interesting NFTs
#28878
By OthersideDeployer
Bored Ape Yacht Club #3749
The Bored Ape Yacht Club is a collection of 10,000 unique Bored Ape NFTs— unique digital collectibles living on the Ethereum blockchain. Your Bored Ape doubles as your Yacht Club membership card, and grants access to members-only benefits, the first of which is access to THE BATHROOM, a collaborative graffiti board. Future areas and perks can be unlocked by the community through roadmap activation.
Fuku-Shiva
The term “Fuku” refers to fortune or good luck. “Shiva” refers to the Hindu deity who represents strongly polar qualities, both severe and delicate. On a beach inspired by adventures on Phi Phi island in Thailand, three youths cavort. Two are representational figures and the third is psychologically rendered. A dynamic relationship ensues between the triad; a reciprocity of active and passive states. The boy on the right engages in maneuvers of evasion, defense, and is dressed in a speedo which reiterates the colors and symbolism of the caution tape on the left and upper right frame of the composition. In concurrent reaction the psychedelic figure shoots out a rocket powered paper airplane. The nude boy seated in the froth and sand approaches in passive repose, and is met with active attention but equal physical reserve by the psychedelic being. Perhaps the most naked figure is also the least representational. Looming large, dynamic, and active, it engages its companions playfully. Various symbols interject into the otherwise naturalistic scene, most notably a beach ball and two contaminated barrels nested in the sand. The upright barrel reads “FukuShima” in Kanji. The barrel laying down reads “Dharma”. To the left the scene is bounded by caution tape, reiterating the danger of the nuclear waste while also hosting alien archetypes, whose presence, as is the nature of these entities, runs up and just behind the consciousness of the psychedelic figure’s eggshell-like skull.
Alien
There are infinite worlds in the Universe with infinite sentient beings inhabiting them. Master autonomously updates once a day at 12am with one of 366 original artworks, showcasing some of the rarest beings, their cities, transport, technology and nature.
ditzyprofitz
Good morning! I'm ditzyprofitz. I'm often referred to as the Neville Longbottom of the group. I'm often described as gullible, and I own it. Will you be the cinammon to my ghost pepper hot sauce?