OpenSea says it's investigating “rumors of an exploit” of smart contracts; CEO says “32 users thus far have signed a malicious payload” and some had NFTs stolen
Emails purporting to be from the NFT marketplace about a planned smart contract migration may have been a phishing attack. Source: @opensea , @dfinzer , and @xanderatallah .
Follow-up coverage characterized the event as a targeted phishing campaign affecting 32 users, clarifying that the suspected compromise centered on malicious signatures rather than a confirmed platform-wide smart-contract failure.
First-order effects
Affected OpenSea users who signed the malicious payload can lose NFTs, while OpenSea must investigate the impersonated migration communications and distinguish phishing from a contract exploit.
OpenSea's CEO and support operations face an immediate trust and incident-response burden as users assess whether requests to sign transactions are legitimate.
NFT sellers and buyers face a less reliable transaction environment when routine contract-migration messaging can be weaponized, raising the importance of clear authorization flows.
Third-order effects
If repeated UI weaknesses and signature-phishing incidents persist, NFT marketplaces will compete not only on liquidity but on whether users can verify listings, emails, and transaction approvals before assets move.
The pattern points to a crypto-marketplace trust gap in which platform branding alone does not secure user-authorized blockchain transactions.
The trend: NFT marketplaces are confronting a security shift from isolated trading-interface flaws to social-engineering attacks that exploit users' transaction signatures.
We are actively investigating rumors of an exploit associated with OpenSea related smart contracts. This appears to be a phishing attack originating outside of OpenSea's website. Do not click links outside of https://opensea.io/.
Update: we still believe this was a phishing attack, and it impacted 32 users 2 hours ago. A thread on the latest updates: https://twitter.com/... Another thread with some technical details: https://twitter.com/... We'll continue monitoring, and posting updates.
Though unconfirmed, the @opensea hack is most likely phishing. Users authorize the “migration” as instructed in the phishing email and the authorization unfortunately allows the hacker to steal the valuable NFTs... https://twitter.com/...
It appears that an attacker is using smart contract 0xa2c0946aD444DCCf990394C5cBe019a858A94 5bD to interact with OpenSea's new exchange contract (v2) I am very unsure how this is working or what is being exploited but it seems that OpenSea's new contract is aboslutely rugged. htt…
In a strange win for transparency, even user-focused phishing attacks are public on the blockchain. Here's the unlucky 19 victims of tonight's attack: https://twitter.com/...
So @opensea released a migration option yesterday and today there are rumors and mass panic in the NFT spaces from users that wallets are being drained of “assets”. 😳 Users are also saying their newly migrated assets are the ones being hit. https://twitter.com/...
This is what a hack looks like 👀 X2Y2 or something else, 578 Ethereum (~$1.7 million) transferred from dozens of wallets through @opensea to a hacker. In addition to possibly millions worth of #NFTs... https://twitter.com/... https://twitter.com/...
Combination of smart contracts that are actually executable code and phishing has hit OpenSea users this afternoon. Question now is whether validly signed smart contracts and immutable transactions on the blockchain makes reversing these transactions impossible? This is painful. …
HEY EVERYONE. I CONNECTED WITH A FEW OTHER PEOPLE WHO GOT HACKED JUST NOW. ALL OF US ONLY HAVE ONE THING IN COMMON. ALL OF OUR STOLEN NFT'S WERE ONES WE MANUALLY MIGRATED ON OPENSEA. @opensea you have so much explaining to do now.
In the wake of a series of viral tweets from panicked traders, NFT marketplace @OpenSea says it's investigating “rumors of an exploit” connected to its smart contracts - a vulnerability that may have cost users valuable tokens. @lil_smush reports https://www.coindesk.com/...
LMAO I CAN'T EVEN RIGHT NOW 😂😂😂😂 😂😂😂😂 😂 Daily reminder @opensea is ran by admitted scammers. What did you expect was going to happen? Going to have a field day with this one https://twitter.com/...