Cointime

Download App
iOS & Android

CertiK Report: OpenSea Phishing Incident Analysis

Validated Project

Introduction

Back in February 2022, OpenSea users were targeted by an elaborate phishing attack through emails that tricked users into signing permissions with a malicious contract. In total, 28 wallets had NFTs stolen that were worth $2 million making it the second most profitable NFT phishing attack in 2022, just behind the Bored Ape Yacht Club (BAYC) Instagram compromise in April 2022.

Event Summary

On 20 February 2022, multiple OpenSea users realized that their NFTs were being transferred out of their wallets and into the wallet of an unknown user. As far as the victims were aware, they hadn’t signed any permissions allowing for the transfer of NFTs. This was particularly concerning considering OpenSea had recently updated the community that they had to migrate their listings.

Users became suspicious that perhaps the new Wyvern 2.3 contract contained a vulnerability, or there may have been a compromise on OpenSea’s main website. However, as only a few individuals were affected those suspicions shifted to a more targeted approach against specific victims. It soon became clear that a phishing email had been sent to multiple victims.

An email from OpenSea advising on migrating listings wasn’t necessarily an unexpected communication to receive. This was a relatively sophisticated phishing campaign as it not only created a sense of urgency within the reader, common among many phishing scams, but it also contained a direct copy/paste text from OpenSea’s Tweet.

Clicking on the link in an email presented the victim with a phishing site, further prompting them to sign an approval which then allowed the attacker to transfer NFTs out of the victims' wallet.

On Chain Analysis

When signing the aforementioned approval, the victims send an AtomicMatch request to the hacker's malicious contract. From there, the AtomicMatch is sent to the Wyvern Exchange contract, confirming the legitimacy of the signed owner’s approval to transfer the NFT. The NFT is then transferred to the exploiters wallet for 0 ETH.

In total, 28 EOAs fell victim to this phishing exploit. A few examples of valuable NFTs stolen were the 2x BAYC and 3x Mutant Ape Yacht Club NFTs. The full list can be seen in the appendix below.

In total, the malicious actor deposited 1105 ETH into Tornado Cash, worth approximately $2.7 million at the time.

OpenSea Warns Users of Future Phishing Attempts

In August, OpenSea issued a warning to its users to be on the lookout for potential phishing emails following a data leak. The NFT exchange detailed that an employee at customer.io misused their company access to download OpenSea users emails which were used by customers to sign up for OpenSea’s newsletter. Due to the phishing attack in February, OpenSea were prepared to inform their users of potential phishing emails promptly.

In late August, an email was sent to OpenSea customers prompting them to recover their MetaMask account by entering their seed phrase. The site mimicked the MetaMask plug-in which was evident by opening the legitimate extension.

This is a slightly different method of phishing as it is attempting to farm seed phrases. In the February attack, the hacker did not attempt to compromise a victim's seed phrase but instead tricked the victim into signing permissions allowing for the transfer of NFTs to the exploiter. The important takeaway here is that there are two types of phishing attacks in Web3.

  1. Classic phishing - Getting a user to send funds to or trick them in to giving away private keys / seed phrases
  2. Ice phishing - Trick a victim into giving a malicious actor approval to transfer assets by signing a transaction.

The OpenSea phishing attack in February falls under the second category and was one of the main methods used to steal users NFTs.

NFTs & Phishing

NFTs have been an attractive target for scammers this year with persistent threat actors targeting projects Discord servers. So far in 2022, we have detected over 730 Discord compromises that have targeted NFT holders. The vast majority of exploits tricked users into signing approvals allowing the attacker to transfer NFTs from the victims to the exploiter.

ncidents of this sort decreased dramatically after detailed investigations uncovered the threat actor responsible for the majority of these compromises. You can read more about the connections between these hacks in our detailed analysis.

Conclusion

NFT holders were a lucrative target for illicit actors in 2022. Users need to be aware that their wallets do not necessarily have to be compromised for their assets to be stolen. In the case of the OpenSea phishing attack, and the majority of phishing attacks, the victims have been tricked in to signing approvals to the attacker. This is why NFT holders need to take special care in verifying that communications are from trusted sources. By following @CertiKAlert on Twitter, you’ll be the first to be alerted on compromises in the NFT space to better help you understand the threats that are out there.

Appendix

List of phished NFTs stolen in the OpenSea phishing attack.

NFT
Comments

All Comments

Recommended for you

  • Iranian Source: Breakthrough in Iran-US Negotiation Preparations Possible 'Tonight or Tomorrow'

    On April 23, an Iranian diplomatic source told RIA Novosti that preparations for negotiations between Iran and the United States in Pakistan may achieve a breakthrough 'tonight or tomorrow.' (Xinhua News Agency)

  • Anthropic's Secondary Market Valuation Reaches $1 Trillion, Surpassing OpenAI

    On April 23, Anthropic's valuation on private equity trading platforms like Forge Global has risen to around $1 trillion, surpassing OpenAI's $880 billion. It is reported that the valuation of this artificial intelligence startup has rapidly increased due to buyers competing to purchase the increasingly scarce secondary market shares of Anthropic. (Dongxin News Agency)

  • BTC Surpasses $78,000

    Market data shows that BTC has surpassed $78,000, currently priced at $78,000.81, with a 24-hour decline of 0.14%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Bitmine Allegedly Acquires 100,000 ETH Worth $233.7 Million

    On April 23, according to monitoring by Lookonchain, three new addresses suspected to be associated with Tom Lee's Bitmine (0xB6a8...9c9E, 0xc2e0...2831, 0x4e5C...276c) received 100,000 ETH from BitGo, valued at $233.7 million.

  • Musk: AI Chip Shortage Expected in the Future

    On April 23, Tesla CEO Elon Musk stated during an earnings call that the company initiated the Terafab chip factory project due to an anticipated severe shortage of AI chips in the future. He remarked, "In terms of industry growth rates, logic chips, and even more so storage chips, we expect to encounter bottlenecks if we do not manufacture chips ourselves. This is the reason for the birth of Terafab." (Dongxin News Agency)

  • US Spot Bitcoin ETF Sees Net Inflow of $331.9 Million Yesterday

    On April 23, according to monitoring by Trader T, the US spot Bitcoin ETF experienced a net inflow of $331.9 million yesterday.

  • US Spot Ethereum ETF Sees Net Inflow of $96.43 Million Yesterday

    On April 23, according to monitoring by Trader T, the US spot Ethereum ETF saw a net inflow of $96.43 million yesterday.

  • U.S. State Department Urges American Citizens to Leave Iran Immediately

    On April 23, the Bureau of Consular Affairs of the U.S. State Department posted on social media that, given Iran's announcement of partial airspace reopening, American citizens in Iran should leave immediately. The post advised U.S. citizens to stay informed about the situation through local media and to consult commercial airlines for information on flights departing Iran. Additionally, U.S. citizens can also travel by land to Armenia, Azerbaijan, Turkey, and Turkmenistan, but should avoid areas along the Iran-Afghanistan, Iran-Iraq, or Iran-Pakistan borders.

  • Tesla: Increasing Investment in AI Computing Power and Advancing New Battery and Material Factories

    On April 23, Tesla's official blog announced that the company is increasing its investment in AI computing power to advance the construction of new battery and battery materials factories. This move is also aimed at further preparing for the production of the third-generation Megapack energy storage system, the Tesla autonomous electric vehicle Cybercab, and the Tesla electric truck Semi.

  • USA: Deploying the Strongest Military Force in History to the Middle East

    On April 23, local time April 22, the U.S. Central Command announced that since the U.S. military began its blockade operations in the waters related to the Strait of Hormuz on April 14, it has requested 31 vessels to turn around or return to port as part of the blockade. The U.S. Central Command also stated that the military is currently deploying the most comprehensive and powerful military force ever seen across the Middle East.