The OpenSea NFT Heist has seen cryptoassets potentially worth millions of dollars stolen from one of the internet’s biggest marketplaces.
While the exact scale of the heist is still being determined, reports are pointing to around 32 users having been affected, with 254 NFTs transferred.
Cybersecurity group Check Point Research (CPR) provided a blow-by-blow account of how the threat actor was able to pull off the massive heist.
The NFT Heist
On February 18th, hackers were able to compromise accounts on OpenSea, a major NFT trading platform.
The scammers took advantage of a planned contract migration, which aimed at addressing existing inactive listings of old NFTs. This saw the company send out a new contract, requiring users to move their listings on the Ethereum blockchain to a new smart contract.
However, hackers hijacked the campaign, and used the same email address from OpenSea to send a fraudulent email to the site’s userbase.
The fake email mimicked OpenSea’s branding and came with a button offering to get the migration process started. It warned users that they have until February 25th to complete the process, or their listings would expire.
Clicking the button took the victim to a phishing website, where they were asked to sign a transaction designed to imitate an official OpenSea one.
The transaction essentially meant that the victim gave approval to the attacker to allow them to transfer NFT’s out of their account. Because it was digitally signed by the victim, OpenSea’s contract considered it authentic, and the tokens were moved from the victim’s wallet to the attackers.
In the end, the hackers were able to transfer NFTs that could be resold for potentially millions of dollars.
Recommended
- How digital waste tracking can help fight climate change
- Edinburgh SaaS firm Sharktower bought by data consultant Proteus
- Consultation to determine UK Huawei 5G ban
According to CPR, a digital wallet connected to the attacks currently has millions of dollars’ worth of Ethereum from selling some of the stolen NFTs.
The exact value is still being determined – OpenSea CEO Devin Finzer said in a Tweet the value was around $1.7 million, but CPR noted that the wallet held closer to $3m in Ethereum.
Some of the NFTs have since been returned.
Keeping NFTs Safe
CPR warned that many websites and projects request a permanent access to NFTs by sending a transaction to sign. The only way to stop this is to manually un-approve the transaction.
In addition, CPR recommend never clicking on links from emails no matter who is the sender. Instead, always try to find the same information on the website provider.
A similar event to the OpenSea NFT heist took place at the start of this year, when one NFT holder had 15 of their tokens stolen in a phishing scam, with the assets valued at around $2.2 million.
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





