29/07/2022 This MetaMask Ethereum Wallet Update May Help Thwart NFT Scams

Following a rash of social media NFT scams, MetaMask adds an extra step that could help users avoid “wallet drainer” attacks.

metamask-nfts-bored-apes-gID_4.jpeg

Social media scams arebooming in the NFT space, with Twitter andDiscord users dupedinto connecting their cryptowalletsto malicioussmart contracts—and having theirNFTsand other tokens swiped as a result. Now the topEthereumwallet,MetaMask, has updated its interface to try and help users recognize and avoid such scams.

MetaMask released a new 10.18.0 update to the wallet this week, which includes a change to the way that the software presents a requested setApprovalForAll permission. Granting that permission allows thesmart contract—the code that powers NFTs anddecentralized apps—the ability to access and transfer out all NFTs andtokensin a wallet.

Following the update, as security firm Wallet Guardnoted on Twitter, MetaMask now makes it clearer that a smart contract is requesting broad permissions, including access to any funds held within the wallet—a function that can be used for so-called “wallet drainer” exploits.

Screenshots posted to MetaMask’sGitHub software development repositoryshow a new prompt that uses a larger font than the rest of the interface. The example text reads, “Give permission to access all of your BAYC?” (orBored Ape Yacht Club), with an additional warning reading, “By granting permission, you are allowing the following account to access your funds.”

MetaMask Software Engineer Alex Donesky wrote on GitHub on June 22 that “there is some urgency to get something out there since this method is so commonly used.” He also added that the “timeline is compressed,” and admitted that it wasn’t how he would approach the change if there was more time to develop it.

Indeed, the update comes following a rash of scams that are primarily spread via hacked social media accounts. In the spring, verified accounts of numerousTwitter users were hijackedand used to share scam links inspired by prominent NFT projects like Azuki andOtherside, and steal the NFTs and tokens of users who unwittingly connected their wallets to the smart contracts.

More recently, the Twitter accounts of various NFT projects and notable collectors were hacked to share similar types of links, billing them as a free NFT or token drop. Such scams have taken place via hacked Discord and Instagram accounts as well. It has led to a debate over whether creators and projectsshould compensate userswho lose assets via such scams.

Earlier this month, NFT drop registration platform Premint was impacted by a hack to its website that used the setApprovalForAll function tosteal an array of valuable NFTs and tokensfrom affected users. Ultimately, the firm reimbursed users to the tune ofover $500,000 worth of ETH, and bought back and returned a pair of pricey NFT collectibles as well.

“The user interface for the most popular wallets need to be drastically improved to make it near impossible for someone to connect to a wallet drainer,” Premint founder Brenden MulligantoldDecryptlast week. “This is a solvable problem, but it’s batshit crazy that it’s so easy to drain a wallet and there aren’t more warnings in place to protect people.”

To be clear, MetaMask’s update does not make any judgment call about the contract that users are attempting to connect to, and does not specifically call out identified scams. Furthermore, there are potentially legitimate uses for the setApprovalForAll function for certain dapps, such as on NFT marketplaces, which only further muddles the user decision.

Still, the MetaMask update could help minimize the impact of scams. Some NFT collectors who have fallen for such social media scams have been accused of recklessly approving transactions due to FOMO and speculative frenzy around NFTs, and this extra step might give users pause—and an opportunity to reconsider their actions.

We’ll see whether MetaMask takes this new feature further in future updates, as well as whether competing wallets will adopt similar techniques. Scams aren’t limited to MetaMask users, after all, and not to Ethereum either.Solanahas a similar function (signAllTransactions), and a notable NFT collector just fell victim to such a scam via hisPhantom wallet.

The pseudonymousco-founder of MonkeDAO, Nom, last nighttweetedabout how his wallet was drained in an attack when he interacted with a smart contract that he thought was safe to use. Nom wrote that he lost about 500 SOL (about $20,200) and NFTs including one fromSolana Monkey Business, which the attacker thensold for 197 SOL($7,736).

Arts

https://decrypt.co/106164/metamask-ethereum-wallet-update-help-thwart-nft-scams?amp=1

Interesting NFTs
Gangnam Wanted Poster #5/25
3L-84574RD, One of the most dangerous robot in Cryptovoxel, last seen in Gangnam near the Rose Nexus. Reward 99000credits battery full or empty. Help us find him, share this!
The Switch
The Switch is a unique, “one of one” NFT that demonstrates the evolution of artwork in the digital realm. The Switch is developed to change form at a specific point of time in the future, known by Pak. The evolution is determined and rendered immutable by smart contracts, or self-executing code on the Ethereum blockchain.
Alex in Wonderland
A figure, Alex, stands mostly naked in the midst of a physical and psychological maelstrom. He is clad only in nostalgic 80’s era socks, on a tenuous island between active waters and a variety of shark denizens. Sharks on the right side of the image are all beached, including a shark with a quartz crystal snout, an orange shark wrapped in a life buoy, and a shark further in the distance wearing an 80’s style shirt with the number “88”. On the left side is the largest shark, wearing bright glossy red lipstick and brandishing prominent teeth with braces. She is cordoned off from the figure by a roped float divider, and within her thought bubble is a warning symbol. Behind the figure, hovering in the air, are Grey aliens emerging from the distance, out of a series of elliptical UFO shaped interdimensional membranes. The Greys take on the visual form of spermazoa ostensibly impregnating the interdimensional thresholds. As is typical, these Greys inhabit a zone just behind the unconscious topology of Alex’s dissociative mind. Though Alex’s bottom half is representative, his top half mutates into a psychological cornucopia. In a manner akin to “Auto-Erotic Sphinx”, a predecessor work, the figure has self suctioned—an act of sensual infatuation, enjoyment, and exploration. Upward exists the figure’s primary conscious eye, adorned with a revolutionary beret emblazoned with a Bitcoin badge. The figure’s summit features the nose of a fighter jet facing off against video game Bullet Bills, one of whom is marked by a communist North Korean star. A cropped section of a UFO observes the contest. Alex’s mind branches both left and right. To the left is more singular embodied consciousness, manifesting two eyes and a Ganesh trunk grasping crayons. The right branch dissociates upward diagonally, emerging into an array of eyes, faces, teeth, tail, a unicorn horn, and much more—all of which participate in expressing his unconscious being; a democracy of psychic factions representing thought impressions and associations. All illumination and darkness– fernal, infernal, high consciousness and corporeal underbelly–reside in this realm. In the distance are relatively languid, light clouds, and against the firmament hovers a colossal distant eye peering over the scene and far beyond. This painting possesses underlying genetic traits with previous works such as “Auto-Erotic Sphinx with Toys”, “Dionysus”, and “Fuku-Shiva”. The work serves also as a nod to an earlier period of art inspiration during late teens and early twenties— born out of the nakedness, vulnerability, curiosity, and wonder inherent to coming of age and all subsequent psychedelic revelation.
Do Nothing (new variant) #7/15
Sometimes
#90297
By OthersideDeployer