NFTs worth millions disappear from prominent Web3 builder’s wallet

1 year ago

Kevin Rose, the laminitis of the NFT postulation Moonbirds, had his idiosyncratic wallet hacked connected January 25, draining it of NFTs worthy millions.

The PROOF corporate laminitis sent retired a Tweet to his 1.6 cardinal followers promising to look into the matter, which has since been connected to a malicious signature Rose granted to the attackers via OpenSea’s Seaport protocol.

Introduced by OpenSea successful May 2022, Seaport is an open-source Web3 protocol that bills itself arsenic “focusing connected trading information and efficiency.” Developed with Solidity Assembly language, Seaport allows for a assortment of functions to instrumentality spot connected the Ethereum blockchain, including the filling of orders, tipping, precocious filtering capabilities and the elimination of redundant transfers.

According to Rose, helium was targeted utilizing a classical lawsuit of societal engineering known arsenic a phishing attack, a cybercrime successful which an attacker tries to instrumentality victims into giving distant delicate information, specified arsenic passwords oregon recognition paper numbers, by disguising themselves arsenic a trustworthy root — successful this lawsuit OpenSea. 

The attackers were capable to marque disconnected with 40 assets, including notable NFTs from projects specified arsenic Cool Cats, OnChainMonkeys, Chromie Squiggles, Autoglyphs, QQL Mint Pass, Admit One Pass, and more. Despite being flagged arsenic stolen and reported to OpenSea arsenic such, respective of them person been re-sold successful the past respective days, including 1 Chromie Squiggle belonging to Rose that sold for 22 WETH. 

It’s not the archetypal clip a salient builder successful Web3 has been targeted by signing a malicious transaction that was past verified by OpenSea’s marketplace contract. Three weeks ago, thieves made disconnected with RTFKT COO NFTs worthy $170,000 drained during a phishing attack. And 3 months ago, a scammer by the sanction of Monkey Drainer made disconnected with implicit $3.5 cardinal dollars worthy of NFTs by besides targeting victims with deceptive phishing techniques. 

Phishing attacks are becoming an progressively prevalent issue. In Q2 2022, phishing attacks accrued by 170% compared to the archetypal quarter, arsenic per a report by the blockchain information steadfast Certik. 

The station NFTs worthy millions vanish from salient Web3 builder’s wallet appeared archetypal connected CryptoSlate.

View source