OpenSea Hack

REPORTED LOSS $2.0M
Medium Access Control ethereum

What happened

The malicious actor sent emails to OpenSea users, which contained information about fake migration to the new contract. In total, 17 users became victims of email fishing.

The malicious actor's address:

https://etherscan.io/address/0x3E0DeFb8…7A8A74

Stolen NFTs list:

https://docs.google.com/spreadsheets/d/1XQNIXuAl2E1XO_cP8pm_vbzskI_Pka4E5sizfcrLITM/edit#gid=0

Stolen NFTs were sold out on LooksRare marketplace, the example transactions:

https://etherscan.io/tx/0xd910c67a…989221

https://etherscan.io/tx/0x9a9bb48a…71e8ee

https://etherscan.io/tx/0x70c8622c…e360f9

Stolen funds were deposited into the Tornado Cash mixer:

https://bloxy.info/txs/transfers_from/0x3e0defb8…7a8a74?currency_id=1

Case & protocol details

Classification NFT / Social Engineering
Protocol Type Exploit/Access control
Official Website opensea.io/
Protocol Twitter/X @opensea

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.