Ultimate magazine theme for WordPress.

The OpenSea phishing scandal reveals a need for security across the NFT landscape

Despite the continued volatility plaguing the digital asset sector, one niche that undoubtedly continues to thrive is the non-fungible token (NFT) market. This is illustrated by the fact that a growing number of mainstream creators such as Coca-Cola, Adidas, the New York Stock Exchange (NYSE) and McDonalds, among many others, have made their way into the burgeoning Metaverse ecosystem in recent years months.

With global NFT sales peaking at $40 billion during 2021 alone, many analysts expect this trend to continue well into the future. For example, the American investment bank Jefferies recently raised its market capitalization forecast for the NFT sector to over USD 35 billion for 2022 and over USD 80 billion for 2025 – a forecast that has also been confirmed by JP Morgan.

However, as with any market that is growing so exponentially, security issues must also be expected. In this context, OpenSea, the well-known marketplace for non-fungible tokens (NFT), recently fell victim to a phishing attack, which took place just hours after the platform announced that it would be delisting its weeks-planned upgrade to remove all inactive NFTs.

Dive into the matter

On February 18, OpenSea announced that it would initiate a smart contract upgrade, requiring all of its users to migrate their listed NFTs from the Ethereum blockchain to a new smart contract. Due to the upgrade, users who did not allow the above migration ran the risk of losing their old and inactive entries.

However, due to the short migration period that OpenSea provides, hackers had a large window of opportunity. Within hours of the announcement, it was revealed that nefarious third parties had launched a sophisticated phishing campaign, stealing NFTs from many users that were stored on the platform before they could be migrated to the new smart contract.

We are actively investigating rumors of an exploit related to OpenSea-related smart contracts. This appears to be a phishing attack originating from outside OpenSea’s website. Do not click on links outside of https://t.co/3qvMZjxmDB.

— OpenSea (@opensea) February 20, 2022

Providing a technical breakdown of the matter, Neeraj Murarka, chief technical officer and co-founder of Bluezelle, a blockchain for the GameFi ecosystem, told Cointelegraph that at the time of the incident, OpenSea was using a protocol called Wyvern, a standard tech module that Most NFT web apps use them as they allow for the management, storage and transfer of these tokens in users’ wallets.

Because the smart contract with Wyvern allowed users to work with the NFTs stored in their “wallets,” the hacker was able to send emails to OpenSea customers posing as representatives of the platform, and they encouraged signing “blind” transactions. Murarka further added:

“Metaphorically, it was like signing a blank check. Usually this is fine if the payee is the intended recipient. Remember that an email can be sent by anyone, but it can appear to have been sent by someone else. In this case, the payee appears to be a lone hacker who was able to use those signed transactions to transfer and effectively steal the NFTs from those users.”

In an interesting turn of events, the hacker apparently returned some of the stolen NFTs to their rightful owners after the incident, with further efforts being made to return other lost assets. Alexander Klus, founder of Creaton, a Web3 content creation platform, had his say on the whole matter, telling Cointelegraph that the phishing email campaign used a malicious signature transaction to authorize all holdings at any time can be deleted. “We need better signature standards (EIP-712) so people can actually see what they’re doing when approving a transaction.”

Finally, Lior Yaffe, co-founder and director of Jelurida, a blockchain software company, pointed out that the episode was a direct result of confusion surrounding OpenSea’s ill-planned smart contract upgrade, as well as the platform’s transaction permissions architecture.

NFT marketplaces need to step up their security game

Murarka believes that web apps leveraging Wyvern’s smart contract system should be complemented with usability improvements to ensure users don’t fall for such phishing attacks over and over again, adding:

“Very clear warnings should be given to educate the user about phishing attacks and drive home the fact that emails are never sent and urge the user to take any action. Web apps like OpenSea should adopt a strict protocol to never communicate with users via email, apart from maybe just registration data.”

However, he acknowledged that even if OpenSea should adopt the most secure security/privacy protocols and standards, it is still up to its users to educate themselves about those risks. “Unfortunately, the web app itself is often blamed even though the user was phished. Who is responsible? The answer is unclear,” he noted.

A similar sentiment is shared by Jessie Chan, chief of staff at ParallelChain Lab, a decentralized blockchain ecosystem, who told Cointelegraph that regardless of how the entire attack was orchestrated, the issue is not entirely dependent on OpenSea’s existing security protocols, but also on awareness the user against phishing. The question remains whether the marketplace operator should have been able to inform its users sufficiently to keep them up to date on how to deal with such scenarios.

Another way to mitigate potential phishing events is to have all interactions between users and their web apps controlled solely through the use of a dedicated mobile/desktop interface. “If all interactions required the use of a desktop app, such attacks could be completely evaded.”

Yaffe presented his perspective on the matter, noting that the main issue – which is at the heart of this whole issue – is the basic architecture of most NFT marketplaces, which allows users to simply get carte blanche permission to use it to sign up to a third-party contract their private wallet without setting a spending limit:

“Since the OpenSea team hasn’t really figured out the source of the phishing operation, it might as well happen again the next time they try to make a change to their architecture.”

what can be done

Murarka noted that the best way to rule out the possibility of these attacks is for people to start using hardware wallets. This is because most software wallets, as well as other custodial storage solutions, are too vulnerable in their general design and operational prospects. He further elaborated: “Similar to Bitcoin, Ethereum etc., NFTs themselves should be moved to hardware wallet accounts instead of keeping them on a centralized platform,” he added:

“Users need to be aware of the risks associated with replying and responding to emails they receive. Emails can be spoofed very easily and users need to be proactive about keeping their crypto assets safe.”

Another thing that NFT owners need to keep in mind is that they should only visit web apps that use high-quality security protocols and verify that the visited marketplaces use the HTTPS mechanism (at least) while showing a lock icon on the can clearly see at the top left of their browser window – correctly pointing to the intended company – when visiting any website.

Yaffe believes users should be cautious with contract approvals and keep an accurate track of the contracts they have greenlit in the past. “Users should revoke unnecessary or unsafe permissions. Whenever possible, users should set a reasonable spending limit with each contract release,” he concludes.

Also See: Cointelegraph Partners with Nitro Network to Bring Digital Mining and Decentralized Internet to the Masses

Finally, Chan believes that users should ideally keep their wallets on a dedicated platform that they don’t use for reading emails or browsing the web, adding that such ways are vulnerable to all kinds of third-party attacks. She further explained:

“It’s inconvenient, but when it comes to high-value assets and there’s no recourse in the event of theft, extreme caution is warranted. And as with all financial transactions, you should choose very carefully who you are dealing with, as the counterparties can also steal your wealth and disappear.”

So, as we move into a future powered by NFTs and other similar novel digital offerings, it remains to be seen how platforms operating in this space will continue to evolve and mature, especially as more and more capital enters the NFT market .

Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers

Comments are closed.

%d bloggers like this: