OpenSea Discord Phishing Hack
While OpenSea is the first and largest NFT marketplace, it is still just as vulnerable to exploit attempts. In February 20, 2022, a phishing attach on OpenSea users resulted in over $1.7 million in Decentraland and Bored Ape Yacht Club tokens were stolen.
The practice of phishing existed since the start of emails and will likely be iterated along with upgrades to the internet. Phishing is “the fraudulent practice of sending emails purporting to be from reputable companies in order to induce individuals to reveal personal information, such as passwords and credit cards.”
With the rise of crypto, wallet recovery phrases are now a new prime target for hackers.
Todays phishing attack wasn’t through email, but through OpenSea’s official discord channel. While hacked, the discord channel reported an official partnership with Youtube and supplied a link claiming to be a free Youtube Genesis Mint Pass.
We are currently investigating a potential vulnerability in our Discord, please do not click on any links in the Discord.
— OpenSea Support (@opensea_support) May 6, 2022