OpenSea Phishing Incident Analysis
ID: 6f9e036e-9708-5b7a-b40a-231926e8779e
STIX ID: report--6f9e036e-9708-5b7a-b40a-231926e8779e
Feed Name: CertiK Blog
In February 2022, a targeted phishing campaign impersonating OpenSea tricked users into approving a malicious contract (an "ice phishing" attack), enabling the attacker to transfer NFTs from 28 wallets—including high-value BAYC and Mutant Ape assets—resulting in roughly $2M in stolen NFTs and 1105 ETH laundered through Tornado Cash; the report also warns of subsequent phishing attempts enabled by an email data leak and emphasizes distinguishing approval-based theft from classic credential/seed-phrase phishing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
