Threat Actor Allegedly Selling Critical Severity OpenSea 0-day Exploit Chain on Hacking Forums
ID: ac5dfa66-0731-521c-94d9-b0e059701d17
STIX ID: report--ac5dfa66-0731-521c-94d9-b0e059701d17
Feed Name: cybersecurityNews.com
A threat actor is reportedly selling a purported critical zero-day exploit chain for OpenSea's Seaport protocol for $100,000 (Bitcoin/Monero); the claimed exploit enables zero-ETH forced transfers of high-value NFTs via signature malleability and cross-collection attacks across Ethereum, Polygon, and Blast. The seller offers PoC code and a live demo, but the listing and technical claims are unverified—no on-chain thefts or IOCs have been observed and OpenSea had not patched or commented as of Feb 14, 2026; users are advised to revoke approvals and monitor listings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
