Jump to content

The (small) Great Apeing - $1.7 million in NFTs stolen in apparent phishing attack on OpenSea users

Lightwreather

Summary

On Saturday, attackers stole hundreds of NFTs from OpenSea users, causing a late-night panic among the site’s broad user base. A spreadsheet compiled by the blockchain security service PeckShield counted 254 tokens stolen over the course of the attack, including tokens from Decentraland and Bored Ape Yacht Club.

 

Quotes

Quote

The bulk of the attacks took place between 5PM and 8PM ET, targeting 32 users in total. Molly White, who runs the blog Web3 is Going Great, estimated the value of the stolen tokens at more than $1.7 million.

The attack appears to have exploited a flexibility in the Wyvern Protocol, the open-source standard underlying most NFT smart contracts, including those made on OpenSea. One explanation (linked by CEO Devin Finzer on Twitter) described the attack in two parts: first, targets signed a partial contract, with a general authorization and large portions left blank. With the signature in place, attackers completed the contract with a call to their own contract, which transferred ownership of the NFTs without payment. In essence, targets of the attack had signed a blank check — and once it was signed, attackers filled in the rest of the check to take their holdings.

“I checked every transaction,” said the user, who goes by Neso. “They all have valid signatures from the people who lost NFTs so anyone claiming they didn’t get phished but lost NFTs is sadly wrong.”

OpenSea was in the process of updating its contract system when the attack took place, but OpenSea has denied that the attack originated with the new contracts. The relatively small number of targets makes such a vulnerability unlikely, since any flaw in the broader platform would likely be exploited on a far greater scale.

Still, many details of the attack remain unclear — particularly the method attackers used to get targets to sign the half-empty contract. Writing on Twitter shortly before 3AM ET, OpenSea CEO Devin Finzer said the attacks had not originated from OpenSea’s website, its various listing systems, or any emails from the company. The rapid pace of the attack — hundreds of transactions in a matter of hours — suggests some common vector of attack, but so far no link has been discovered.
“We’ll keep you updated as we learn more about the exact nature of the phishing attack,” said Finzer on Twitter. “If you have specific information that could be useful, please DM @opensea_support.”

 

My thoughts

So, it appears that someone used a combinaiton of Phishing and Contractual loopholes to steal (scam) people out of a major amout of Crypto. I don't really know what to say apart from the usual phishing prevention advice - Do not click on any random links, make sure that they are from official sources. If it's too good to be true it likely is, no company is gonna ask for your personal details over email, yada yada yada.

 

Sources

TheVerge

Spreadsheet

Web3isgoinggreat (The irony/sarcasm is strong with this one)

Twitter

"A high ideal missed by a little, is far better than low ideal that is achievable, yet far less effective"

 

If you think I'm wrong, correct me. If I've offended you in some way tell me what it is and how I can correct it. I want to learn, and along the way one can make mistakes; Being wrong helps you learn what's right.

Link to comment
Share on other sites

Link to post
Share on other sites

And nothing of value was lost.

Corps aren't your friends. "Bottleneck calculators" are BS. Only suckers buy based on brand. It's your PC, do what makes you happy.  If your build meets your needs, you don't need anyone else to "rate" it for you. And talking about being part of a "master race" is cringe. Watch this space for further truths people need to hear.

 

Ryzen 7 5800X3D | ASRock X570 PG Velocita | PowerColor Red Devil RX 6900 XT | 4x8GB Crucial Ballistix 3600mt/s CL16

Link to comment
Share on other sites

Link to post
Share on other sites

It took longer than I expected for someone to think of right click and Save As.

CPU: Ryzen 9 3900X | Cooler: Noctua NH-D15S | MB: Gigabyte X570 Aorus Elite | RAM: G.SKILL Ripjaws V 32GB 3600MHz | GPU: EVGA RTX 3080 FTW3 Ultra | Case: Fractal Design Define R6 Blackout | SSD1: Samsung 840 Pro 256GB | SSD2: Samsung 840 EVO 500GB | HDD1: Seagate Barracuda 2TB | HDD2: Seagate Barracuda 4TB | Monitors: Dell S2716DG + Asus MX259H  | Keyboard: Ducky Shine 5 (Cherry MX Brown) | PSU: Corsair RMx 850W

Link to comment
Share on other sites

Link to post
Share on other sites

 

Corps aren't your friends. "Bottleneck calculators" are BS. Only suckers buy based on brand. It's your PC, do what makes you happy.  If your build meets your needs, you don't need anyone else to "rate" it for you. And talking about being part of a "master race" is cringe. Watch this space for further truths people need to hear.

 

Ryzen 7 5800X3D | ASRock X570 PG Velocita | PowerColor Red Devil RX 6900 XT | 4x8GB Crucial Ballistix 3600mt/s CL16

Link to comment
Share on other sites

Link to post
Share on other sites

Damn, and here I was absolutely convinced the blockchain made scams and theft impossible! How can this be?

Spoiler

/S

It's almost like snake oil brokers like OpenSea are actually less trustworthy and reliable than banks and VISA, go figure. Smart contracts are not contracts, they're programs; and software is the devil's playground.

 

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to comment
Share on other sites

Link to post
Share on other sites

OOH no.. People falling for a Glorified Pyramid scheme got scammed, NOO the Horror.

 

 

╔═════════════╦═══════════════════════════════════════════╗
║__________________║ hardware_____________________________________________________ ║
╠═════════════╬═══════════════════════════════════════════╣
║ cpu ______________║ ryzen 9 5900x_________________________________________________ ║
╠═════════════╬═══════════════════════════════════════════╣
║ GPU______________║ ASUS strix LC RX6800xt______________________________________ _║
╠═════════════╬═══════════════════════════════════════════╣
║ motherboard_______ ║ asus crosshair formulla VIII______________________________________║
╠═════════════╬═══════════════════════════════════════════╣
║ memory___________║ CMW32GX4M2Z3600C18 ______________________________________║
╠═════════════╬═══════════════════════════════════════════╣
║ SSD______________║ Samsung 980 PRO 1TB_________________________________________ ║
╠═════════════╬═══════════════════════════════════════════╣
║ PSU______________║ Corsair RM850x 850W _______________________ __________________║
╠═════════════╬═══════════════════════════════════════════╣
║ CPU cooler _______ ║ Be Quiet be quiet! PURE LOOP 360mm ____________________________║
╠═════════════╬═══════════════════════════════════════════╣
║ Case_____________ ║ Thermaltake Core X71 __________________________________________║
╠═════════════╬═══════════════════════════════════════════╣
║ HDD_____________ ║ 2TB and 6TB HDD ____________________________________________║
╠═════════════╬═══════════════════════════════════════════╣
║ Front IO__________   ║ LG blu-ray drive & 3.5" card reader, [trough a 5.25 to 3.5 bay]__________║
╠═════════════╬═══════════════════════════════════════════╣ 
║ OS_______________ ║ Windows 10 PRO______________________________________________║
╚═════════════╩═══════════════════════════════════════════╝

 

Link to comment
Share on other sites

Link to post
Share on other sites

10 hours ago, Just Monika said:

It took longer than I expected for someone to think of right click and Save As.

This was a sophisticated NFT heist. The perps had to PrtSc, open MS Paint and paste the items and then save them, which took them all night to clear the inventory. They had stealth on their side tho, which gave them all the time they needed without any worries of raising an alarm.

Link to comment
Share on other sites

Link to post
Share on other sites

9 minutes ago, Sauron said:

image.png.3e225b7f0387e1c7600030f106189c6d.png

They had to use "Awesome Screenshot" so it's worth more than your regular screenie - Just awesome in fact.
Now all they have to do is get them all fully documented to that end....
 

"If you ever need anything please don't hesitate to ask someone else first"..... Nirvana
"Whadda ya mean I ain't kind? Just not your kind"..... Megadeth
Speaking of things being "All Inclusive", Hell itself is too.

 

Link to comment
Share on other sites

Link to post
Share on other sites

40f.png

 

 

Inb4 Media calling Phishing attacks 'hacking' and blaming it on 'Hackers'. 

People, especially those with hundreds of thousands USD assets in their accounts seriously need some cyber security training. I wouldn't be surprised if some of their passwords even were 'password'. 

Gaming HTPC:

R5 5600X - Cryorig C7 - Asus ROG B350-i - EVGA RTX2060KO - 16gb G.Skill Ripjaws V 3333mhz - Corsair SF450 - 500gb 960 EVO - LianLi TU100B


Desktop PC:
R9 3900X - Peerless Assassin 120 SE - Asus Prime X570 Pro - Powercolor 7900XT - 32gb LPX 3200mhz - Corsair SF750 Platinum - 1TB WD SN850X - CoolerMaster NR200 White - Gigabyte M27Q-SA - Corsair K70 Rapidfire - Logitech MX518 Legendary - HyperXCloud Alpha wireless


Boss-NAS [Build Log]:
R5 2400G - Noctua NH-D14 - Asus Prime X370-Pro - 16gb G.Skill Aegis 3000mhz - Seasonic Focus Platinum 550W - Fractal Design R5 - 
250gb 970 Evo (OS) - 2x500gb 860 Evo (Raid0) - 6x4TB WD Red (RaidZ2)

Synology-NAS:
DS920+
2x4TB Ironwolf - 1x18TB Seagate Exos X20

 

Audio Gear:

Hifiman HE-400i - Kennerton Magister - Beyerdynamic DT880 250Ohm - AKG K7XX - Fostex TH-X00 - O2 Amp/DAC Combo - 
Klipsch RP280F - Klipsch RP160M - Klipsch RP440C - Yamaha RX-V479

 

Reviews and Stuff:

GTX 780 DCU2 // 8600GTS // Hifiman HE-400i // Kennerton Magister
Folding all the Proteins! // Boincerino

Useful Links:
Do you need an AMP/DAC? // Recommended Audio Gear // PSU Tier List 

Link to comment
Share on other sites

Link to post
Share on other sites

A fool and his money are soon parted,  how soon?  crt C crt V soon. 

 

I personally blame Microsoft for making the shortcuts so easily available, they should be charged with aiding piracy and made to refund everyone's money. 

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

How much is $1.7m worth of NFT? Is it similar to $1.7m in Monopoly money? 

| Intel i7-3770@4.2Ghz | Asus Z77-V | Zotac 980 Ti Amp! Omega | DDR3 1800mhz 4GB x4 | 300GB Intel DC S3500 SSD | 512GB Plextor M5 Pro | 2x 1TB WD Blue HDD |
 | Enermax NAXN82+ 650W 80Plus Bronze | Fiio E07K | Grado SR80i | Cooler Master XB HAF EVO | Logitech G27 | Logitech G600 | CM Storm Quickfire TK | DualShock 4 |

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, xAcid9 said:

How much is $1.7m worth of NFT? Is it similar to $1.7m in Monopoly money? 

Depends if you are the type of player that also keeps a ledger so you can increase the banks debt ceiling and make the game go longer.   In which case it's about $2 of monopoly money and the boot piece. 

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

Saying "unhackable blockchain" is like saying "unsinkable ships" or "unbreakable car".

 

It doesn't mean it cannot be happen. It means that when it happens, there is no recovery nor mitigation in place. With blockchain, it means that when an hack happens, it is irreversible, it is done. 

Link to comment
Share on other sites

Link to post
Share on other sites

3 hours ago, xAcid9 said:

How much is $1.7m worth of NFT? Is it similar to $1.7m in Monopoly money? 

It's like 500.000 Uno +5 cards.

Link to comment
Share on other sites

Link to post
Share on other sites

So a funny monke is actually smarter than a human being with (de)evolved "brain". Breaking news!

DAC/AMPs:

Klipsch Heritage Headphone Amplifier

Headphones: Klipsch Heritage HP-3 Walnut, Meze 109 Pro, Beyerdynamic Amiron Home, Amiron Wireless Copper, Tygr 300R, DT880 600ohm Manufaktur, T90, Fidelio X2HR

CPU: Intel 4770, GPU: Asus RTX3080 TUF Gaming OC, Mobo: MSI Z87-G45, RAM: DDR3 16GB G.Skill, PC Case: Fractal Design R4 Black non-iglass, Monitor: BenQ GW2280

Link to comment
Share on other sites

Link to post
Share on other sites

5 hours ago, xAcid9 said:

How much is $1.7m worth of NFT? Is it similar to $1.7m in Monopoly money? 

How much is it....Ask the IRS. they will gladly fine you for failing to report those assets. making the fines higher than the value of those NFT's

╔═════════════╦═══════════════════════════════════════════╗
║__________________║ hardware_____________________________________________________ ║
╠═════════════╬═══════════════════════════════════════════╣
║ cpu ______________║ ryzen 9 5900x_________________________________________________ ║
╠═════════════╬═══════════════════════════════════════════╣
║ GPU______________║ ASUS strix LC RX6800xt______________________________________ _║
╠═════════════╬═══════════════════════════════════════════╣
║ motherboard_______ ║ asus crosshair formulla VIII______________________________________║
╠═════════════╬═══════════════════════════════════════════╣
║ memory___________║ CMW32GX4M2Z3600C18 ______________________________________║
╠═════════════╬═══════════════════════════════════════════╣
║ SSD______________║ Samsung 980 PRO 1TB_________________________________________ ║
╠═════════════╬═══════════════════════════════════════════╣
║ PSU______________║ Corsair RM850x 850W _______________________ __________________║
╠═════════════╬═══════════════════════════════════════════╣
║ CPU cooler _______ ║ Be Quiet be quiet! PURE LOOP 360mm ____________________________║
╠═════════════╬═══════════════════════════════════════════╣
║ Case_____________ ║ Thermaltake Core X71 __________________________________________║
╠═════════════╬═══════════════════════════════════════════╣
║ HDD_____________ ║ 2TB and 6TB HDD ____________________________________________║
╠═════════════╬═══════════════════════════════════════════╣
║ Front IO__________   ║ LG blu-ray drive & 3.5" card reader, [trough a 5.25 to 3.5 bay]__________║
╠═════════════╬═══════════════════════════════════════════╣ 
║ OS_______________ ║ Windows 10 PRO______________________________________________║
╚═════════════╩═══════════════════════════════════════════╝

 

Link to comment
Share on other sites

Link to post
Share on other sites

43 minutes ago, darknessblade said:

How much is it....Ask the IRS. they will gladly fine you for failing to report those assets. making the fines higher than the value of those NFT's

image.png.1b49aae96186ea59db79c7fe7eb8647b.png

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×