New Exploit Found in Old OpenSea Contract Could Lead to User NFT Theft

Pocket Universe tweeted that a new exploit has been discovered in an old OpenSea contract that could lead to the theft of user NFTs. The founder of SlowMist said that the exploit calls the upgradeTo function of the target contract 0xE0c.... .7b4e of the upgradeTo function, which is part of: OwnableDelegateProxy of OpenSea Wyvern Protocol.

If the target user confirms the wallet pop-up box, upgradeTo is called to change the default assigned implementation address to the phisher's own malicious contract address. The phisher then steals the target user's previously listed NFTs on OpenSea (before May 2022) through the malicious contract.

Source

OpenSea

NFT

Security Incidents

Related News
Bybit hackers move over half the stolen ETH onto Bitcoin, largely using ThorChain Bybit hackers move over half the stolen ETH onto Bitcoin, largely using ThorChain
Stablecoin neobank Infini exploited for $49 million: security analysts Stablecoin neobank Infini exploited for $49 million: security analysts
Sony’s Soneium debuts its first music NFT collection with crypto record label Sony’s Soneium debuts its first music NFT collection with crypto record label
NoOnes CEO Ray Youssef discloses $8 million exploit weeks after the fact, confirming crypto sleuth ZachXBT's investigation NoOnes CEO Ray Youssef discloses $8 million exploit weeks after the fact, confirming crypto sleuth ZachXBT's investigation
Arbitrum, Azuki-backed Animecoin unveils tokenomics with over 50% community allocation Arbitrum, Azuki-backed Animecoin unveils tokenomics with over 50% community allocation
Latest News More More
3 Days Ago Argentine prosecutor seeks to freeze $110 million in proceeds tied to Libra memecoin scandal: report
3 Days Ago Mt. Gox moves over $1 billion worth of bitcoin to unmarked address: Arkham
4 Days Ago Ethereum devs activate Pectra upgrade on Sepolia testnet in last phase before mainnet rollout
4 Days Ago Binance Records $3.97B Weekly Inflows
4 Days Ago MEXC Partners With Hacken to Increase Security Standards
delate
Use TokenInsight App All Crypto Insights Are In Your Hands
Open