21/02/2022 $1.7 million in NFTs stolen in apparent phishing attack on OpenSea users

Two hundred and fifty-four tokens were stolen over roughly three hours

Illustration by Alex Castro / The Verge

On Saturday, attackers stole hundreds of NFTs from OpenSea users, causing a late-night panic among the site’s broad user base.A spreadsheet compiled by the blockchain security service PeckShield counted 254 tokens stolen over the course of the attack, including tokens from Decentraland and Bored Ape Yacht Club.

The bulk of the attacks took place between 5PM and 8PM ET, targeting 32 users in total. Molly White, who runs the blog Web3 is Going Great, estimated the value of the stolen tokens at more than $1.7 million.

“They all have valid signatures”

The attack appears to have exploited a flexibility inthe Wyvern Protocol, the open-source standard underlying most NFT smart contracts, including those made on OpenSea. One explanation (linked by CEO Devin Finzeron Twitter) described the attack in two parts: first, targets signed a partial contract, with a general authorization and large portions left blank. With the signature in place, attackers completed the contract with a call to their own contract, which transferred ownership of the NFTs without payment. In essence, targets of the attack had signed a blank check — and once it was signed, attackers filled in the rest of the check to take their holdings.

“I checked every transaction,” saidthe user, who goes by Neso. “They all have valid signatures from the people who lost NFTs so anyone claiming they didn’t get phished but lost NFTs is sadly wrong.”

Valued at $13 billion in a recent funding round, OpenSea has becomeone of the most valuable companies of the NFT boom, providing a simple interface for users to list, browse, and bid on tokens without interacting directly with the blockchain. That success has come with significant security issues, as the company has struggled with attacks that leveragedold contractsorpoisoned tokensto steal users’ valuable holdings.

OpenSea was in the process of updating its contract system when the attack took place, but OpenSea has denied that the attack originated with the new contracts. The relatively small number of targets makes such a vulnerability unlikely, since any flaw in the broader platform would likely be exploited on a far greater scale.

Still, many details of the attack remain unclear — particularly the method attackers used to get targets to sign the half-empty contract. Writing on Twitter shortly before 3AM ET, OpenSea CEO Devin Finzer said the attacks had not originated fromOpenSea’s website,its various listing systems, orany emails from the company. The rapid pace of the attack — hundreds of transactions in a matter of hours — suggests some common vector of attack, but so far no link has been discovered.

“We’ll keep you updated as we learn more about the exact nature of the phishing attack,” said Finzer on Twitter. “If you have specific information that could be useful, please DM@opensea_support.”

Arts

https://www.theverge.com/2022/2/20/22943228/opensea-phishing-hack-smart-contract-bug-stolen-nft

Interesting NFTs
AntlerCat | Daffodil / Elk Tra
Uh, hi! I'm AntlerCat | Daffodil / Elk Tra. I want to live in a world where people believe the world is flat. I would give it all up to be on Oprah. It's pawesome to meet you!
Smile to Shreds, Neon Gwen
The First KayPikeFashion Mint Ever. Ever feel so joyful and were grinning so hard you felt you could split in half? That punk rebel yell of glee when you pull of a particularly refined stunt? This is the paint of dreams, fangs and neon. Hellish and hard to pull off. I was able to with this work quietly paint a sweet inner tale of childhood influences, rat fink and autobody shops. All while pretending to paint gwenom for the audience. More on that in bonus material. This is my alternate animation made specifically for crypto art collectors. It will only ever exist in this format. You get the Shiny, unused in media verified image. More on that in the bonus material. Mixed Media: Bio/Digital. Glycerin on 5'9" human skin 10-14 hours Performance art. Shot on Canon EOS RP. 16 + hours Photoshop and DaVinci Resolve. All Works are SFW. Art has been Seen on the front page of Reddit, Featured in the New York Times, Galileo.tv, and multiple other promotions including Twitch.tv, Disney Interactive, RIOT games, WB games, AMD and more! More on how this art is unique and potentially explosive in the NFT world: https://youtu.be/CXbNF2Y6srs ------------------------- The purchase of this NFT Grants the buyer unique bonus material. Physical Mail Bonus Package: A verified physical Art Print. Autographed from the artist in 12x16. Please allow a few weeks for delivery. Digital Bonus Package: This image in .mp4. An "About the Art" Video and an "From the Artist" introduction. A README.txt about the artwork with some personal notes and Links relevant to the artwork.
Who is Satoshi Nakamoto?
"Who is Satoshi Nakamoto?" is dedicated to the mysterious creation of Bitcoin, and acts as the showcase artwork within Javier ArrĂ©s’ exploratory series "Bitcoin, The Origin". "Who is the creator of Bitcoin?" The artist, ArrĂ©s, explores this question, and the feelings of doubt and mystery that accompany it, through his unique artistic language. An unknown, an enigma. It should be remembered that the name Satoshi Nakamoto is a pseudonym of Bitcoin's author or authors and gives us little insight into its true creator. For this Visual Toy, ArrĂ©s uses the signature claw machine, his famous half-operation, to symbolize our collective ignorance and unconfirmed belief: As soon as it has the stuffed animal within its grasp and appears to have solved the puzzle, the animal escapes again, and again. At present, there are three more public and studied possibilities who are either believed to be the creators of the currency or who directly claim the creation of it. It may be all or none of them, yet these three personalities leave us clues which are an important part of this interesting enigma. For this moment, it will remain unknown... In this artwork, ArrĂ©s elevates the claw machine from the apparatus, to an iconic pop art object serving as an important element to the Bitcoin creation narrative. Action is everywhere, with each movement serving an iconographical or metaphorical purpose related directly to cryptocurrency: Various ups and downs, roller coasters, mining points, robot, coins and more speak to a sense of hope, risk, mystery, randomness and possibility of pay out. Hundreds of manically thought out details make this creation one of the artist’s most complex Visual Toys to date. ------- "Bitcoin, The Origin" is a set of two Visual Toys, titled "Who is Satoshi Nakamoto" and "It’s Alive!" which reflect and explore the mystery and enigmas behind the creation of Bitcoin. ArrĂ©s presents these proposals to us in his signature style, full of iconography, fantasy, maniacal animations and a panoply of details (both subtle and overt) which simultaneously fascinate, hypnotize, and narrate this historical milestone through the singular vision of the artist. Through this series, ArrĂ©s freezes a crucial moment of cryptocurrency history, taking a still photo under his vision and turning it into two unique crypto artworks. ---- More info about Javier ArrĂ©s: https://javierarres.com/about.html
Alex in Wonderland
A figure, Alex, stands mostly naked in the midst of a physical and psychological maelstrom. He is clad only in nostalgic 80’s era socks, on a tenuous island between active waters and a variety of shark denizens. Sharks on the right side of the image are all beached, including a shark with a quartz crystal snout, an orange shark wrapped in a life buoy, and a shark further in the distance wearing an 80’s style shirt with the number “88”. On the left side is the largest shark, wearing bright glossy red lipstick and brandishing prominent teeth with braces. She is cordoned off from the figure by a roped float divider, and within her thought bubble is a warning symbol. Behind the figure, hovering in the air, are Grey aliens emerging from the distance, out of a series of elliptical UFO shaped interdimensional membranes. The Greys take on the visual form of spermazoa ostensibly impregnating the interdimensional thresholds. As is typical, these Greys inhabit a zone just behind the unconscious topology of Alex’s dissociative mind. Though Alex’s bottom half is representative, his top half mutates into a psychological cornucopia. In a manner akin to “Auto-Erotic Sphinx”, a predecessor work, the figure has self suctioned—an act of sensual infatuation, enjoyment, and exploration. Upward exists the figure’s primary conscious eye, adorned with a revolutionary beret emblazoned with a Bitcoin badge. The figure’s summit features the nose of a fighter jet facing off against video game Bullet Bills, one of whom is marked by a communist North Korean star. A cropped section of a UFO observes the contest. Alex’s mind branches both left and right. To the left is more singular embodied consciousness, manifesting two eyes and a Ganesh trunk grasping crayons. The right branch dissociates upward diagonally, emerging into an array of eyes, faces, teeth, tail, a unicorn horn, and much more—all of which participate in expressing his unconscious being; a democracy of psychic factions representing thought impressions and associations. All illumination and darkness– fernal, infernal, high consciousness and corporeal underbelly–reside in this realm. In the distance are relatively languid, light clouds, and against the firmament hovers a colossal distant eye peering over the scene and far beyond. This painting possesses underlying genetic traits with previous works such as “Auto-Erotic Sphinx with Toys”, “Dionysus”, and “Fuku-Shiva”. The work serves also as a nod to an earlier period of art inspiration during late teens and early twenties— born out of the nakedness, vulnerability, curiosity, and wonder inherent to coming of age and all subsequent psychedelic revelation.
#51552
By OthersideDeployer