{"id":220790,"date":"2022-02-21T16:30:30","date_gmt":"2022-02-21T16:30:30","guid":{"rendered":"https:\/\/cryptoslate.com\/?p=220790"},"modified":"2022-03-22T22:29:25","modified_gmt":"2022-03-22T22:29:25","slug":"opensea-phishing-attack-heres-what-happened","status":"publish","type":"post","link":"https:\/\/cryptoslate.com\/opensea-phishing-attack-heres-what-happened\/","title":{"rendered":"OpenSea phishing attack, here\u2019s what happened"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">Another attack on users of the NFT marketplace OpenSea emerged yesterday February 20th. As <\/span><a href=\"https:\/\/cryptoslate.com\/opensea-suffers-phishing-attack-users-lose-nft-worth-millions\/\"><span style=\"font-weight: 400;\">reported<\/span><\/a><span style=\"font-weight: 400;\"> by <em>CryptoSlate<\/em>, the CEO of the NFT marketplace, Devin Finzer, <\/span><a href=\"https:\/\/twitter.com\/dfinzer\/status\/1495245308812402688?s=21\"><span style=\"font-weight: 400;\">tweeted<\/span><\/a><span style=\"font-weight: 400;\"> that it\u2019s likely a phishing attack and not connected to the platform directly. However, he pointed out that investigations were still ongoing.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Blockchain records show that hackers were able to get access to users\u2019 wallets and steal several NFTs. So far, NFTs stolen include Bored Apes, Mutant Apes, and several other popular collections. The attacker stole close to $2 million worth of NFT.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The gist of the modus operandi of the attacker is that the attacker launched a smart contract on the Ethereum blockchain over a month prior to the actual thefts. It\u2019s evident that the attacker was planning the operation well in advance. The attacker then sent several users emails urging them to move their NFTs from an old <\/span><a href=\"https:\/\/cryptoslate.com\/products\/opensea\/\"><span style=\"font-weight: 400;\">OpenSea<\/span><\/a><span style=\"font-weight: 400;\"> smart contract to a new one; the new contract was developed to address bugs discovered after an earlier attack.<\/span><\/p>\n<h2><strong>Attacker mimicked a genuine OpenSea email<\/strong><\/h2>\n<p><span style=\"font-weight: 400;\">OpenSea did send a genuine email to users asking them to transition their NFTs to the new contract. The attacker imitated the OpenSea email, but with links pointing to the attacker's smart contract.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This false contract, in turn, initiated signing of open sell orders of users\u2019 NFTs, which the attacker collected without making any rushed attempt to steal the NFTs. These NFTs were up for sale, and the attacker used a very obscure signing message, difficult for users to interpret correctly. The signature essentially sold the NFTs for zero ether (<\/span><a href=\"https:\/\/cryptoslate.com\/coins\/ethereum\/\"><span style=\"font-weight: 400;\">ETH<\/span><\/a><span style=\"font-weight: 400;\">) to the attacker.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In a follow-up <\/span><a href=\"https:\/\/twitter.com\/NadavAHollander\/status\/1495509511179755530\"><span style=\"font-weight: 400;\">tweet<\/span><\/a><span style=\"font-weight: 400;\">, OpenSea CTO Nadav Hollander shared a technical run-down of the phishing attacks targeting OpenSea users.<\/span><\/p>\n<blockquote><p><span style=\"font-weight: 400;\">\u201cAll of the malicious orders contain valid signatures from the affected users, indicating that they did sign an order somewhere, at some point in time. However, none of these orders were broadcasted to OpenSea at the time of signing,\u201d Hollander tweets.<\/span><\/p><\/blockquote>\n<p><span style=\"font-weight: 400;\">According to Hollander, None of the malicious orders were executed against the new Wyvern 2.3 contract, indicating that they were signed before the migration and are unlikely to be related to OpenSea\u2019s migration flow. A Wyvern contract is a decentralized digital asset exchange protocol running on <\/span><a href=\"https:\/\/cryptoslate.com\/news\/ethereum\/\"><span style=\"font-weight: 400;\">Ethereum<\/span><\/a><span style=\"font-weight: 400;\">, and utilized by OpenSea to facilitate NFT trading on its platform.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201c32 users had NFTs stolen over a relatively short time period.\u00a0 This is extremely unfortunate, but suggests a targeted attack as opposed to a systemic issue. This information, coupled with our discussions with impacted users and investigation by security experts, suggests a phishing operation that was executed ahead of the deprecation of the [older and buggy] 2.2 contract given the impending invalidation of these collected malicious orders,\u201d Hollander tweets.<\/span><\/p>\n<h2><strong>New contract supports EIP-712 typed data payloads<\/strong><\/h2>\n<p><span style=\"font-weight: 400;\">The new 2.3 version of the Wyvern contracts implement the Ethereum Improvement Proposal (EIP) 712, which among other things supports so-called typed data payloads which makes it much more difficult for bad actors to trick someone into signing an order without realizing it.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The phishing email sent by the attacker told users to sign a message to login on OpenSea and migrate sell orders to the new Opensea <\/span><a href=\"https:\/\/wyvernprotocol.com\/\"><span style=\"font-weight: 400;\">Wyvern<\/span><\/a><span style=\"font-weight: 400;\"> 2.3 contract. Instead, users signed a private sale for zero ETH of the NFTs to the attacker. The attacker then executed the smart contract function to steal the NFTs before their listings expired. The attacker was able to do so because he had saved the user's signature.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Additionally, as explained in a <\/span><a href=\"https:\/\/twitter.com\/0xfoobar\/status\/1495324659604144131?s=28\"><span style=\"font-weight: 400;\">tweet<\/span><\/a><span style=\"font-weight: 400;\"> by smart contract developer \u201cfoobar\u201d, the attacker was able to steal the NFTs in batches, not needing to make the sales one by one.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201cA single malicious signature can rug <\/span><i><span style=\"font-weight: 400;\">all<\/span><\/i><span style=\"font-weight: 400;\"> [foobar\u2019s emphasis] of your approved OpenSea NFTs. No need to sign an individual sell order for each one, as originally assumed,\u201d foobar tweets. Normally, the atomicMatch_()-function in the smart contract is invoked twice to buy two NFTs, but the attacker called atomicMatch_() once to buy 21 NFTs.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">According to foobar, there is a \u201cdelegatecall\u201d, which means &#8220;take the code at target address, and execute it within the current context.\u201d<\/span><\/p>\n<blockquote><p><span style=\"font-weight: 400;\">\u201cThis is a dangerous pattern, because it means you're subject to code injection. And that's exactly what happened. The contract with approval permissions to move the NFTs requested code from the malicious helper contract, and that code said &#8220;transfer all NFTs to me&#8221;,\u201d foobar tweets.<\/span><\/p><\/blockquote>\n<h2><strong>A malicious signature can take all of a user's NFTs<\/strong><\/h2>\n<p><span style=\"font-weight: 400;\">This is a novel attack vector, according to foobar. The assumption that one signature equals one NFT does not hold. A malicious signature can take all of a user's NFTs in a single transaction.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">OpenSea CTO Nadav Hollander tweets that users need to learn to watch out for malicious off-chain signing messages, just as the community has learned not to share seed phrases or submitting unknown transactions. Hollander also calls for standardizing EIP-712 and EIP-4361.<\/span><\/p>\n<blockquote><p><span style=\"font-weight: 400;\">\u201cWe as a community must move to standardizing off-chain signatures using EIP-712 typed data or other agreed-upon standards like EIP-4361 (the &#8220;Sign in with Ethereum&#8221; method).\u201d<\/span><\/p><\/blockquote>\n<p><span style=\"font-weight: 400;\">\u201cOn this point, you'll notice that all new orders signed on OpenSea (including migrated orders) use the new EIP-712 format \u2014 a change of any kind is understandably scary, but this change actually makes signing much safer as you can better see what you're signing,\u201d Hollander tweets.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">As for the investigation of the incident, the team at OpenSea is still in the middle of their research, in cooperation with the affected users.<\/span><\/p>\n<blockquote><p><span style=\"font-weight: 400;\">\u201cWe\u2019re actively working with users whose items were stolen to narrow down a set of common websites that they interacted with that might have been responsible for the malicious signatures. Huge thanks to the users that hopped on the phone with us directly,\u201d OpenSea CEO Devin Finzer <a href=\"https:\/\/twitter.com\/dfinzer\/status\/1495302791564120069\">tweets.<\/a><\/span><\/p><\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>Another attack on users of the NFT marketplace OpenSea emerged yesterday February 20th. As reported by CryptoSlate, the CEO of the NFT marketplace, Devin Finzer, tweeted that it\u2019s likely a phishing attack and not connected to the platform directly. However, he pointed out that investigations were still ongoing. Blockchain records show that hackers were able [&hellip;]<\/p>\n","protected":false},"author":962,"featured_media":220791,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[76799],"tags":[72190,76325,76956,76704,77421],"prediction_market_topic":[],"post_folder":[],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.9 (Yoast SEO v21.9.1) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>OpenSea phishing attack, here\u2019s what happened<\/title>\n<meta name=\"description\" content=\"The phishing attack against users of the popular OpenSea NFT marketplace, was planned well ahead of the actual theft of user\u2019s NFT. The attacker utilized both phishing email tactics and exploited dated smart contracts.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cryptoslate.com\/opensea-phishing-attack-heres-what-happened\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"OpenSea phishing attack, here\u2019s what happened\" \/>\n<meta property=\"og:description\" content=\"The phishing attack against users of the popular OpenSea NFT marketplace, was planned well ahead of the actual theft of user\u2019s NFT. The attacker utilized both phishing email tactics and exploited dated smart contracts.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cryptoslate.com\/opensea-phishing-attack-heres-what-happened\/\" \/>\n<meta property=\"og:site_name\" content=\"CryptoSlate\" \/>\n<meta property=\"article:published_time\" content=\"2022-02-21T16:30:30+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-03-22T22:29:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cryptoslate.com\/wp-content\/uploads\/2022\/02\/opensea-phishing.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1100\" \/>\n\t<meta property=\"og:image:height\" content=\"619\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Laszlo Dobos\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@cryptoslate\" \/>\n<meta name=\"twitter:site\" content=\"@cryptoslate\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Laszlo Dobos\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"NewsArticle\",\"@id\":\"https:\/\/cryptoslate.com\/opensea-phishing-attack-heres-what-happened\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/cryptoslate.com\/opensea-phishing-attack-heres-what-happened\/\"},\"author\":{\"@type\":\"Person\",\"@id\":\"https:\/\/cryptoslate.com\/author\/laszlo-dobos\/#person\",\"name\":\"Laszlo Dobos\",\"url\":\"https:\/\/cryptoslate.com\/author\/laszlo-dobos\/\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/cryptoslate.com\/author\/laszlo-dobos\/\"},\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/cryptoslate.com\/author\/laszlo-dobos\/#authorimage\",\"url\":\"https:\/\/cryptoslate.com\/wp-content\/uploads\/2021\/12\/lars-dobos-author-300x300.jpg\",\"contentUrl\":\"https:\/\/cryptoslate.com\/wp-content\/uploads\/2021\/12\/lars-dobos-author-300x300.jpg\",\"caption\":\"Laszlo Dobos\"},\"jobTitle\":\"Reporter\",\"description\":\"Educated in computer engineering, Laszlo began developing an interest for crypto and blockchain technology back in 2013. Lars started writing about IT and IT...\",\"worksFor\":{\"@id\":\"https:\/\/cryptoslate.com\/#organization\"},\"sameAs\":[\"https:\/\/x.com\/larsdobos\",\"https:\/\/www.linkedin.com\/in\/lars-dobos-26356a3\"]},\"headline\":\"OpenSea phishing attack, here\u2019s what happened\",\"datePublished\":\"2022-02-21T16:30:30+00:00\",\"dateModified\":\"2022-03-22T22:29:25+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/cryptoslate.com\/opensea-phishing-attack-heres-what-happened\/\"},\"wordCount\":970,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/cryptoslate.com\/#organization\"},\"keywords\":[\"ethereum\",\"hacks\",\"NFTs\",\"OpenSea\",\"phishing\"],\"articleSection\":[\"Crime\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/cryptoslate.com\/opensea-phishing-attack-heres-what-happened\/#respond\"]}],\"copyrightYear\":\"2022\",\"copyrightHolder\":{\"@id\":\"https:\/\/cryptoslate.com\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/cryptoslate.com\/opensea-phishing-attack-heres-what-happened\/\",\"url\":\"https:\/\/cryptoslate.com\/opensea-phishing-attack-heres-what-happened\/\",\"name\":\"OpenSea phishing attack, here\u2019s what happened\",\"isPartOf\":{\"@id\":\"https:\/\/cryptoslate.com\/#website\"},\"datePublished\":\"2022-02-21T16:30:30+00:00\",\"dateModified\":\"2022-03-22T22:29:25+00:00\",\"description\":\"The phishing attack against users of the popular OpenSea NFT marketplace, was planned well ahead of the actual theft of user\u2019s NFT. The attacker utilized both phishing email tactics and exploited dated smart contracts.\",\"breadcrumb\":{\"@id\":\"https:\/\/cryptoslate.com\/opensea-phishing-attack-heres-what-happened\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/cryptoslate.com\/opensea-phishing-attack-heres-what-happened\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/cryptoslate.com\/opensea-phishing-attack-heres-what-happened\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/cryptoslate.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"OpenSea phishing attack, here\u2019s what happened\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/cryptoslate.com\/#website\",\"url\":\"https:\/\/cryptoslate.com\/\",\"name\":\"CryptoSlate\",\"description\":\"Cryptocurrency News and Real-time Coin Data\",\"publisher\":{\"@id\":\"https:\/\/cryptoslate.com\/#organization\"},\"inLanguage\":\"en-US\"},{\"@type\":\"NewsMediaOrganization\",\"@id\":\"https:\/\/cryptoslate.com\/#organization\",\"name\":\"CryptoSlate\",\"url\":\"https:\/\/cryptoslate.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/cryptoslate.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/cryptoslate.com\/wp-content\/uploads\/2018\/05\/c-logo.jpg\",\"contentUrl\":\"https:\/\/cryptoslate.com\/wp-content\/uploads\/2018\/05\/c-logo.jpg\",\"width\":1000,\"height\":1000,\"caption\":\"CryptoSlate\"},\"image\":{\"@id\":\"https:\/\/cryptoslate.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/twitter.com\/cryptoslate\",\"https:\/\/www.instagram.com\/cryptoslate\",\"https:\/\/www.linkedin.com\/company\/cryptoslate\",\"https:\/\/www.youtube.com\/c\/cryptoslate\",\"https:\/\/cryptoslate.substack.com\",\"https:\/\/t.me\/cryptoslatenews\",\"https:\/\/www.crunchbase.com\/organization\/cryptoslate\",\"https:\/\/iq.wiki\/wiki\/cryptoslate\",\"https:\/\/news.google.com\/publications\/CAAqKggKIiRDQklTRlFnTWFoRUtEMk55ZVhCMGIzTnNZWFJsTG1OdmJTZ0FQAQ\",\"https:\/\/muckrack.com\/media-outlet\/cryptoslate\",\"https:\/\/www.tiktok.com\/@cryptoslatenews\"],\"publishingPrinciples\":\"https:\/\/cryptoslate.com\/editorial-policy\/#editorial-principles\",\"ownershipFundingInfo\":\"https:\/\/cryptoslate.com\/disclaimers\/how-cryptoslate-makes-and-spends-money\/\",\"correctionsPolicy\":\"https:\/\/cryptoslate.com\/editorial-policy\/#corrections-feedback\",\"ethicsPolicy\":\"https:\/\/cryptoslate.com\/editorial-policy\/#editorial-principles\",\"foundingDate\":\"2017-08-04\",\"founder\":[{\"@type\":\"Person\",\"name\":\"Nate Whitehill\"},{\"@type\":\"Person\",\"name\":\"Matthew Blancarte\"}],\"contactPoint\":[{\"@type\":\"ContactPoint\",\"contactType\":\"customer support\",\"url\":\"https:\/\/cryptoslate.com\/contact\/\",\"availableLanguage\":\"en-US\"},{\"@type\":\"ContactPoint\",\"contactType\":\"sales\",\"url\":\"https:\/\/cryptoslate.com\/advertising\/\",\"availableLanguage\":\"en-US\"},{\"@type\":\"ContactPoint\",\"contactType\":\"newsroom\",\"url\":\"https:\/\/cryptoslate.com\/editorial-policy\/#corrections-feedback\",\"email\":\"tips@cryptoslate.com\",\"availableLanguage\":\"en-US\"}],\"masthead\":\"https:\/\/cryptoslate.com\/about\/#masthead\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/cryptoslate.com\/#\/schema\/person\/dda2470a7ceed819679f90d50a7d3055\",\"name\":\"Laszlo Dobos\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/cryptoslate.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/cryptoslate.com\/wp-content\/uploads\/2021\/12\/lars-dobos-author-150x150.jpg\",\"contentUrl\":\"https:\/\/cryptoslate.com\/wp-content\/uploads\/2021\/12\/lars-dobos-author-150x150.jpg\",\"caption\":\"Laszlo Dobos\"},\"description\":\"Educated in computer engineering, Laszlo began developing an interest for crypto and blockchain technology back in 2013. Lars started writing about IT and IT-security as a full-time tech journalist and editor in 2007. He's a self-employed entrepreneur and writer deep down the famous rabbit hole. When he's not spending too much time in the crypto space or reading history books, Lars enjoys the outdoors, food and hanging out with friends.\",\"url\":\"https:\/\/cryptoslate.com\/author\/laszlo-dobos\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"OpenSea phishing attack, here\u2019s what happened","description":"The phishing attack against users of the popular OpenSea NFT marketplace, was planned well ahead of the actual theft of user\u2019s NFT. The attacker utilized both phishing email tactics and exploited dated smart contracts.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cryptoslate.com\/opensea-phishing-attack-heres-what-happened\/","og_locale":"en_US","og_type":"article","og_title":"OpenSea phishing attack, here\u2019s what happened","og_description":"The phishing attack against users of the popular OpenSea NFT marketplace, was planned well ahead of the actual theft of user\u2019s NFT. The attacker utilized both phishing email tactics and exploited dated smart contracts.","og_url":"https:\/\/cryptoslate.com\/opensea-phishing-attack-heres-what-happened\/","og_site_name":"CryptoSlate","article_published_time":"2022-02-21T16:30:30+00:00","article_modified_time":"2022-03-22T22:29:25+00:00","og_image":[{"width":1100,"height":619,"url":"https:\/\/cryptoslate.com\/wp-content\/uploads\/2022\/02\/opensea-phishing.jpg","type":"image\/jpeg"}],"author":"Laszlo Dobos","twitter_card":"summary_large_image","twitter_creator":"@cryptoslate","twitter_site":"@cryptoslate","twitter_misc":{"Written by":"Laszlo Dobos","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/cryptoslate.com\/opensea-phishing-attack-heres-what-happened\/#article","isPartOf":{"@id":"https:\/\/cryptoslate.com\/opensea-phishing-attack-heres-what-happened\/"},"author":{"@type":"Person","@id":"https:\/\/cryptoslate.com\/author\/laszlo-dobos\/#person","name":"Laszlo Dobos","url":"https:\/\/cryptoslate.com\/author\/laszlo-dobos\/","mainEntityOfPage":{"@id":"https:\/\/cryptoslate.com\/author\/laszlo-dobos\/"},"image":{"@type":"ImageObject","@id":"https:\/\/cryptoslate.com\/author\/laszlo-dobos\/#authorimage","url":"https:\/\/cryptoslate.com\/wp-content\/uploads\/2021\/12\/lars-dobos-author-300x300.jpg","contentUrl":"https:\/\/cryptoslate.com\/wp-content\/uploads\/2021\/12\/lars-dobos-author-300x300.jpg","caption":"Laszlo Dobos"},"jobTitle":"Reporter","description":"Educated in computer engineering, Laszlo began developing an interest for crypto and blockchain technology back in 2013. Lars started writing about IT and IT...","worksFor":{"@id":"https:\/\/cryptoslate.com\/#organization"},"sameAs":["https:\/\/x.com\/larsdobos","https:\/\/www.linkedin.com\/in\/lars-dobos-26356a3"]},"headline":"OpenSea phishing attack, here\u2019s what happened","datePublished":"2022-02-21T16:30:30+00:00","dateModified":"2022-03-22T22:29:25+00:00","mainEntityOfPage":{"@id":"https:\/\/cryptoslate.com\/opensea-phishing-attack-heres-what-happened\/"},"wordCount":970,"commentCount":0,"publisher":{"@id":"https:\/\/cryptoslate.com\/#organization"},"keywords":["ethereum","hacks","NFTs","OpenSea","phishing"],"articleSection":["Crime"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/cryptoslate.com\/opensea-phishing-attack-heres-what-happened\/#respond"]}],"copyrightYear":"2022","copyrightHolder":{"@id":"https:\/\/cryptoslate.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/cryptoslate.com\/opensea-phishing-attack-heres-what-happened\/","url":"https:\/\/cryptoslate.com\/opensea-phishing-attack-heres-what-happened\/","name":"OpenSea phishing attack, here\u2019s what happened","isPartOf":{"@id":"https:\/\/cryptoslate.com\/#website"},"datePublished":"2022-02-21T16:30:30+00:00","dateModified":"2022-03-22T22:29:25+00:00","description":"The phishing attack against users of the popular OpenSea NFT marketplace, was planned well ahead of the actual theft of user\u2019s NFT. The attacker utilized both phishing email tactics and exploited dated smart contracts.","breadcrumb":{"@id":"https:\/\/cryptoslate.com\/opensea-phishing-attack-heres-what-happened\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cryptoslate.com\/opensea-phishing-attack-heres-what-happened\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/cryptoslate.com\/opensea-phishing-attack-heres-what-happened\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cryptoslate.com\/"},{"@type":"ListItem","position":2,"name":"OpenSea phishing attack, here\u2019s what happened"}]},{"@type":"WebSite","@id":"https:\/\/cryptoslate.com\/#website","url":"https:\/\/cryptoslate.com\/","name":"CryptoSlate","description":"Cryptocurrency News and Real-time Coin Data","publisher":{"@id":"https:\/\/cryptoslate.com\/#organization"},"inLanguage":"en-US"},{"@type":"NewsMediaOrganization","@id":"https:\/\/cryptoslate.com\/#organization","name":"CryptoSlate","url":"https:\/\/cryptoslate.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cryptoslate.com\/#\/schema\/logo\/image\/","url":"https:\/\/cryptoslate.com\/wp-content\/uploads\/2018\/05\/c-logo.jpg","contentUrl":"https:\/\/cryptoslate.com\/wp-content\/uploads\/2018\/05\/c-logo.jpg","width":1000,"height":1000,"caption":"CryptoSlate"},"image":{"@id":"https:\/\/cryptoslate.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/twitter.com\/cryptoslate","https:\/\/www.instagram.com\/cryptoslate","https:\/\/www.linkedin.com\/company\/cryptoslate","https:\/\/www.youtube.com\/c\/cryptoslate","https:\/\/cryptoslate.substack.com","https:\/\/t.me\/cryptoslatenews","https:\/\/www.crunchbase.com\/organization\/cryptoslate","https:\/\/iq.wiki\/wiki\/cryptoslate","https:\/\/news.google.com\/publications\/CAAqKggKIiRDQklTRlFnTWFoRUtEMk55ZVhCMGIzTnNZWFJsTG1OdmJTZ0FQAQ","https:\/\/muckrack.com\/media-outlet\/cryptoslate","https:\/\/www.tiktok.com\/@cryptoslatenews"],"publishingPrinciples":"https:\/\/cryptoslate.com\/editorial-policy\/#editorial-principles","ownershipFundingInfo":"https:\/\/cryptoslate.com\/disclaimers\/how-cryptoslate-makes-and-spends-money\/","correctionsPolicy":"https:\/\/cryptoslate.com\/editorial-policy\/#corrections-feedback","ethicsPolicy":"https:\/\/cryptoslate.com\/editorial-policy\/#editorial-principles","foundingDate":"2017-08-04","founder":[{"@type":"Person","name":"Nate Whitehill"},{"@type":"Person","name":"Matthew Blancarte"}],"contactPoint":[{"@type":"ContactPoint","contactType":"customer support","url":"https:\/\/cryptoslate.com\/contact\/","availableLanguage":"en-US"},{"@type":"ContactPoint","contactType":"sales","url":"https:\/\/cryptoslate.com\/advertising\/","availableLanguage":"en-US"},{"@type":"ContactPoint","contactType":"newsroom","url":"https:\/\/cryptoslate.com\/editorial-policy\/#corrections-feedback","email":"tips@cryptoslate.com","availableLanguage":"en-US"}],"masthead":"https:\/\/cryptoslate.com\/about\/#masthead"},{"@type":"Person","@id":"https:\/\/cryptoslate.com\/#\/schema\/person\/dda2470a7ceed819679f90d50a7d3055","name":"Laszlo Dobos","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cryptoslate.com\/#\/schema\/person\/image\/","url":"https:\/\/cryptoslate.com\/wp-content\/uploads\/2021\/12\/lars-dobos-author-150x150.jpg","contentUrl":"https:\/\/cryptoslate.com\/wp-content\/uploads\/2021\/12\/lars-dobos-author-150x150.jpg","caption":"Laszlo Dobos"},"description":"Educated in computer engineering, Laszlo began developing an interest for crypto and blockchain technology back in 2013. Lars started writing about IT and IT-security as a full-time tech journalist and editor in 2007. He's a self-employed entrepreneur and writer deep down the famous rabbit hole. When he's not spending too much time in the crypto space or reading history books, Lars enjoys the outdoors, food and hanging out with friends.","url":"https:\/\/cryptoslate.com\/author\/laszlo-dobos\/"}]}},"_links":{"self":[{"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/posts\/220790"}],"collection":[{"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/users\/962"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/comments?post=220790"}],"version-history":[{"count":9,"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/posts\/220790\/revisions"}],"predecessor-version":[{"id":220823,"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/posts\/220790\/revisions\/220823"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/media\/220791"}],"wp:attachment":[{"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/media?parent=220790"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/categories?post=220790"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/tags?post=220790"},{"taxonomy":"prediction_market_topic","embeddable":true,"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/prediction_market_topic?post=220790"},{"taxonomy":"post_folder","embeddable":true,"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/post_folder?post=220790"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}