How did RM7.1 million in NFTs get stolen through a phishing incident?

Last Saturday, Devin Finzer, co-founder and CEO of OpenSea—the “largest” non-fungible token (NFT) marketplace—tweeted to confirm of a phishing incident involving 254 stolen tokens. A hacker has tricked 32 victims into signing “a malicious payload” that authorised the transfer of their NFTs to the attacker for free.

“I know you’re all worried. We’re running an all hands on deck investigation,” said Finzer.

Blockchain security service PeckShield compiled the list of the 254 tokens stolen over the course of the attack, with an estimated value of more than USD 1.7 million (RM7.1 million). The tokens included tokens from Decentraland—a 3D virtual world where users can buy virtual plots of land in the platform as NFTs—and Bored Ape Yacht Club—which in one way or another resulted in this really creepy interview on Jimmy Fallon.

Finzer added that he doesn’t believe that the attack is “connected to the OpenSea website”. However, the attack occurred during OpenSea’s migration to its new Wyvern smart contract system—a “decentralized digital asset exchange protocol running on Ethereum”. The migration began on Friday and will only be completed by 25 February.

“The upgrade ensures that old, inactive listings expire, enables bulk cancellation with a single, low-cost transaction, and allows us to roll out new features like bulk cancellation and more descriptive signatures,” wrote Finzer.

Finzer also linked a Twitter thread explaining how the attack happened. The targets first signed a partial contract, with a general authorisation and large portions left blank. With their signatures, the attacker completed the contract on ther own, which allowed them to transfer ownership to the NFTs without payment. But this didn’t explain the method attackers used to get targets to sign the half-empty contract. 

“We’re actively working with users whose items were stolen to narrow down a set of common websites that they interacted with that might have been responsible for the malicious signatures,” said Finzer.

Phishing incidents on the internet are sadly quite common, but it’s probably the first time I’m hearing about a major phishing incident involving something and new and lawless like NFTs. It’s always important to remember not to sign anything you don’t fully trust, or give any of your important information either.

[ SOURCE, IMAGE SOURCE ]

Recent Posts

RedMagic Astra 2 Malaysia: Snapdragon 8 Elite Gen 5 tablet with 185Hz OLED display, promo priced from RM3,599

RedMagic has officially launched its 2026 flagship gaming tablet in Malaysia, the RedMagic Astra 2.…

7 hours ago

TNG eWallet records over RM1 billion inbound tourist spend during Visit Malaysia 2026

TNG Digital announced that international tourists spent over RM1 billion using TNG eWallet during the…

8 hours ago

KTMB EMUPlus adds Bandar Tasik Selatan stop from 4 to 6 September: Here’s what you need to know

Keretapi Tanah Melayu Berhad (KTMB) is adding Bandar Tasik Selatan as a temporary stop for…

8 hours ago

BYD Atto 3 Performance coming to Malaysia: 443hp AWD, 470km range, 220kW DC charging

Sime Motors will be expanding the 2026 BYD Atto 3 lineup with a new variant:…

9 hours ago

Xiaomi debuts Mijia Front Load Washer Dryer Pro in Malaysia for as low as RM2,399

In addition to the Redmi Note 17 Series, Xiaomi has also rolled out several new…

10 hours ago

Xiaomi Smart Band 11 Active, Redmi Watch 6 Series Malaysia: Promo price starts from RM119

The Redmi Note 17 Series might have been the star of Xiaomi’s big launch event…

11 hours ago

This website uses cookies.