{"id":18483,"date":"2022-02-20T13:03:21","date_gmt":"2022-02-20T12:03:21","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=18483"},"modified":"2022-02-20T13:03:27","modified_gmt":"2022-02-20T12:03:27","slug":"openseas-short-deadline-opens-window-of-opportunity-for-hackers","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/openseas-short-deadline-opens-window-of-opportunity-for-hackers\/","title":{"rendered":"OpenSea&#8217;s Short Deadline Opens Window of Opportunity for Hackers"},"content":{"rendered":"\n<p>Investigations showed&nbsp;that &nbsp;NFTs were stolen from users&nbsp;via <a href=\"https:\/\/coinscreed.com\/staging\/what-happened-to-the-60-million-raised-by-this-defi-project-with-a-dog-theme.html\" data-type=\"post\" data-id=\"12991\">phishing emails<\/a> before being moved to OpenSea's new smart contract. The attackers acquire&nbsp;access to the NFTs after a user allows the migration via the phishing email.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"640\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/02\/image-268-1024x640.png\" alt=\"OpenSea's Short Deadline Opens Window of Opportunity for Hackers \" class=\"wp-image-18492\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/02\/image-268-1024x640.png 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/02\/image-268-300x188.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/02\/image-268-768x480.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/02\/image-268-750x469.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/02\/image-268.png 1043w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><a href=\"https:\/\/www.google.com\/search?q=OpenSea%27s+Short+Deadline+Opens+Window+of+Opportunity+for+Hackers&oq=OpenSea%27s+Short+Deadline+Opens+Window+of+Opportunity+for+Hackers&aqs=chrome..69i57.974j0j7&sourceid=chrome&ie=UTF-8\" data-type=\"URL\" data-id=\"https:\/\/www.google.com\/search?q=OpenSea%27s+Short+Deadline+Opens+Window+of+Opportunity+for+Hackers&oq=OpenSea%27s+Short+Deadline+Opens+Window+of+Opportunity+for+Hackers&aqs=chrome..69i57.974j0j7&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noopener\">OpenSea<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>, an online non-fungible token marketplace, has begun investigating exploit reports, claiming in a recent tweet that it has most likely been the target of a fishing assault. After it was revealed that a hacker stole millions of dollars worth of non-fungible tokens, the <a href=\"https:\/\/coinscreed.com\/staging\/new-york-stock-exchange-might-launch-an-nft-market-soon.html\" data-type=\"post\" data-id=\"18289\">NFT community <\/a>was ablaze with conjecture earlier today.&nbsp;<\/p>\n\n\n\n<p>The firm announced the introduction of a new improved smart contract on Saturday, inviting customers to move their listings without incurring gas fees before the deadline on Feb. 25. The <a href=\"https:\/\/coinscreed.com\/staging\/cross-chain-router-protocol-multichain-recovers-about-50-of-its-stolen-funds-from-hackers.html\" data-type=\"post\" data-id=\"18475\">hacker<\/a>, on the other hand, has opted to take advantage of the update by using legitimate-looking phishing emails to dupe customers into handing over their NFTs. Users are advised not to click any links outside of the official website, according to the business.<\/p>\n\n\n\n<p>PeckShield, a <a href=\"https:\/\/coinscreed.com\/staging\/applied-blockchain-to-build-a-trustless-bridge-connecting-algorand-and-ethereum.html\" data-type=\"post\" data-id=\"18389\">blockchain <\/a>security startup, has disclosed the full list of NFTs taken by the malicious <a href=\"https:\/\/coinscreed.com\/staging\/polygon-native-stablecoin-project-qi-dao-faces-exploit-of-about-13m-on-superfluid-vested-contract.html\" data-type=\"post\" data-id=\"18020\">attacker<\/a>. They're worth around $3 million in total.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"how-the-urgency-and-short-deadline-helped-the-hacker\">How the urgency and short deadline helped the hacker<\/h2>\n\n\n\n<p>Due to the urgency and short timeframe, hackers had a narrow window of opportunity. Within hours of OpenSea's upgrade announcement, various sources began reporting on an ongoing attack on the soon-to-be-delisted NFTs.<\/p>\n\n\n\n<p>Further analysis indicated that the NFTs were stolen via phishing emails before being moved to OpenSea's new <a href=\"https:\/\/coinscreed.com\/staging\/turkish-ev-maker-togg-partners-with-ava-labs.html\" data-type=\"post\" data-id=\"16249\">smart contract<\/a>. The attackers acquire access to the NFTs after a user allows the migration via the fake email.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"534\" height=\"222\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/02\/image-261.png\" alt=\"OpenSea's Short Deadline Opens Window of Opportunity for Hackers \" class=\"wp-image-18485\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/02\/image-261.png 534w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/02\/image-261-300x125.png 300w\" sizes=\"(max-width: 534px) 100vw, 534px\" \/><\/figure>\n\n\n\n<p>Users should be weary of all emails from OpenSea and revoke all rights related to the migration to the new smart contract.<\/p>\n\n\n\n<p>Devin Finzer, co-founder and CEO of <a href=\"https:\/\/coinscreed.com\/staging\/opensea-refund-users-who-lost-nfts-from-the-inactive-listing-exploit-about-1-8m-in-ethereum.html\" data-type=\"post\" data-id=\"17519\">OpenSea<\/a>, confirmed that 32 users had lost NFTs as a result of the phishing assault. While the NFT marketplace has yet to decipher the ongoing phishing campaign, blockchain investigator Peckshield suspects a probable loss of user data (including email addresses) that is fueling the ongoing phishing attack.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"549\" height=\"230\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/02\/image-262.png\" alt=\"OpenSea's Short Deadline Opens Window of Opportunity for Hackers \" class=\"wp-image-18486\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/02\/image-262.png 549w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/02\/image-262-300x126.png 300w\" sizes=\"(max-width: 549px) 100vw, 549px\" \/><\/figure>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\u201cIf you are concerned and want to protect yourself, you can un-approve access to your <a href=\"https:\/\/coinscreed.com\/staging\/nft-whales-are-swooning-over-the-adidas-originals-collection.html\" data-type=\"post\" data-id=\"18392\">NFT <\/a>collection.\u201d<\/p><\/blockquote>\n\n\n\n<p>Three NFTs were confiscated by Her Majesty's Revenue and Customs (HMRC), the UK's principal <a href=\"https:\/\/coinscreed.com\/staging\/kazakhstans-president-reportedly-calls-for-tax-increase-on-crypto-mining.html\" data-type=\"post\" data-id=\"18008\">tax <\/a>department, in connection with a suspected tax evasion scheme.<\/p>\n\n\n\n<p>According to reports, the suspects built 250 counterfeit &#8220;shell&#8221; firms and utilized fictitious identities to escape 1.4 million <a href=\"https:\/\/coinscreed.com\/staging\/ripple-powered-usd-settlement-service-for-corporate-clients-is-now-available-from-saudi-british-bank.html\" data-type=\"post\" data-id=\"13076\">British <\/a>pounds (approximately $1.8 million) in value-added taxes.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Investigations showed&nbsp;that &nbsp;NFTs were stolen from users&nbsp;via phishing emails before being moved to OpenSea&#8217;s new smart contract. The attackers acquire&nbsp;access to the NFTs after a user allows the migration via the phishing email. OpenSea , an online non-fungible token marketplace, has begun investigating exploit reports, claiming in a recent tweet that it has most likely [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":18492,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[6115,5370,5716,7326],"class_list":["post-18483","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-hackers-2","tag-nfts-2","tag-opensea-2","tag-smartcontract"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/02\/image-268.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/18483","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=18483"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/18483\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/18492"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=18483"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=18483"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=18483"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}