Hundreds of NFTs stolen from OpenSea wallets - here's what you need to know

CryptoKitties NFT
(Image credit: CryptoKitties)

Hundreds of non-fungible tokens (NFTs) have been stolen from the accounts of OpenSea users after a series of successful phishing attacks, it has emerged.

The NFT marketplace was alerted to the issue over the weekend when a handful of customers discovered tokens missing from their wallets. Word of the incident quickly spread, causing a stir in the NFT community.

In an attempt to calm the panic, OpenSea chief executive Devin Finzer took to Twitter, explaining that the attacks were not the result of a security vulnerability in the platform, but rather a phishing campaign targeting NFT owners.

TechRadar needs you!

We're looking at how our readers use VPNs with different devices so we can improve our content and offer better advice. This survey shouldn't take more than 60 seconds of your time. Thank you for taking part.

>> Click here to start the survey in a new window <<

A list compiled by blockchain security company PeckShield suggests that more than 250 NFTs were stolen, including items from popular collections such as Bored Ape Yacht Club. Although some have since been recovered, wallet analysis shows the stolen tokens have earned the attacker roughly $1.7 million in sell-on value.

OpenSea NFTs stolen

NFTs are representations of digital properties such as images or videos, often described as digital collectibles. What makes them different from traditional collectibles (for example, Fortnite skins) is that each NFT has a distinct signature that demonstrates its uniqueness and allows for ownership of the associated asset to be verified and traced.

Once the playtoy of an enthusiast minority, NFTs now change hands for many millions of dollars over platforms like OpenSea, which is itself valued at $13 billion.

Inevitably, the valuations of the NFTs exchanged over OpenSea and the notoriety of the marketplace have attracted increased attention from hackers. In the last few months, the company has had to close off security bugs that allowed hackers to purchase NFTs for well below value and create malicious tokens that could drain the crypto wallets of victims.

Now, OpenSea is facing down another security issue, the details of which still remain murky.

“Our team has been working around the clock to investigate the specific details of this phishing attack,” explained OpenSea via its official Twitter account.

“We’ve narrowed down the list of impacted individuals to 17, rather than the previously mentioned 32. Our original count included anyone who had interacted with the attacker, rather than those who were victims of the phishing attack.”

However, the precise mechanism of the attack remains unclear. Early signs point towards a manipulation of the Wyvern Protocol on which most NFT smart contracts are built. According to a Twitter thread referenced by Finzer, the attacker tricked the victims into signing half of a Wyvern order, allowing for their NFTs to be transferred to a new wallet without payment.

Finzer says there is no evidence the affected users had been targeted via email, and the identity of the website used to facilitate the attack remains a mystery.

The advice for concerned OpenSea users is to “double check you are interacting with opensea.io in your browser when you sign messages” and to “un-approve access to your NFT collection” via Etherscan.

TechRadar Pro has asked OpenSea whether it has plans to put in place measures to prevent users from falling victim to similar phishing scams in future.

Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Read more
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Phishing campaign targets prominent X users, accounts at risk
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
LastPass 2022 hack fallout continues with millions of dollars more reportedly stolen
Bitcoin
Fake Ledger data breach emails used to trick victims into giving up recovery phrases
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Microsoft reveals over a million PCs hit by malvertising campaign
Ethereum
Hackers steal over $1bn in one of the biggest crypto thefts ever
Data leak
AWS customers hit by major cyberattack which then stored stolen credentials in plain sight
Latest in Security
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Latest in News
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 9 (game #1140)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 9 (game #371)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 9 (game #637)
WhatsApp
WhatsApp just made its AI impossible to avoid – but at least you can turn it off