{"id":2702,"date":"2022-03-18T02:52:12","date_gmt":"2022-03-18T08:52:12","guid":{"rendered":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/?p=2702"},"modified":"2022-03-18T02:55:02","modified_gmt":"2022-03-18T08:55:02","slug":"all-my-apes-gone","status":"publish","type":"post","link":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/2022\/03\/18\/all-my-apes-gone\/","title":{"rendered":"All My Apes Gone"},"content":{"rendered":"\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" data-src=\"https:\/\/i.kym-cdn.com\/entries\/icons\/mobile\/000\/039\/182\/Screen_Shot_2021-12-30_at_3.07.00_PM.jpg\" alt=\"\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" class=\"lazyload\" \/><figcaption>All my apes are gone from Know your meme<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-embed-aspect-16-9 wp-has-aspect-ratio wp-block-paragraph\">With the NFT market being worth more than $10 billion, it has definitely gained the attention of a lot of people. From NFTs being talked about on the news, to celebrities, public figures and giant companies supporting or even starting NFT projects, it would make sense why hackers and malicious actors have decided to exploit the weaknesses in the system. And in this post, I would like to talk about some ways people have exploited these weaknesses in the system.<\/p>\n\n\n\n<p class=\"wp-embed-aspect-16-9 wp-has-aspect-ratio wp-block-paragraph\">Before I start, you should know how NFTs or Non Fungible Tokens work, and since there is a lot that goes on with NFTs, I can not explain everything so I would direct you to this link: <a href=\"https:\/\/www.dummies.com\/article\/business-careers-money\/personal-finance\/cryptocurrency\/nfts-for-dummies-cheat-sheet-289345\">Click here<\/a><\/p>\n\n\n\n<h3 class=\"wp-embed-aspect-16-9 wp-has-aspect-ratio wp-block-heading\">OpenSea email Scam<\/h3>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" data-src=\"https:\/\/www.pcrisk.com\/images\/stories\/screenshots202202\/opensea-email-scam-main.jpg\" alt=\"\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" class=\"lazyload\" \/><figcaption>OpenSea email phishing email from PCrisk<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-embed-aspect-16-9 wp-has-aspect-ratio wp-block-paragraph\">For this attack, unsuspecting users receive an email claiming to be from <a href=\"https:\/\/opensea.io\/about\">OpenSea<\/a>, and if they were to click the link it would lead them to a fraudulent website, and ask them to connect their wallet, it would then ask them sign the &#8220;Approve All&#8221; transaction, which would then let the attacker initiate transactions from their wallet. With that, they are then able to sell the NFTs in the victims&#8217; wallet to themselves for 0 ETH, or way lower than what they are worth. <\/p>\n\n\n\n<p class=\"wp-embed-aspect-16-9 wp-has-aspect-ratio wp-block-paragraph\">According to OpenSea, 17 users fell victim to this attack, and the attacker made stole numerous &#8220;valuable&#8221; assets such as: 3 Bored Ape Yacht Club, 2 Clonex, 17 Azuki, and 631 ETH. Everything is estimated to cost at least $1.7 million<\/p>\n\n\n\n<p class=\"wp-embed-aspect-16-9 wp-has-aspect-ratio wp-block-paragraph\">Phishing attacks are the most common types of attacks used for stealing NFTs.<\/p>\n\n\n\n<h3 class=\"wp-embed-aspect-16-9 wp-has-aspect-ratio wp-block-heading\">LandMine NFTs<\/h3>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"twitter-tweet\"><blockquote class=\"twitter-tweet\" data-lang=\"en\"><p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/opensea?ref_src=twsrc%5Etfw\">@opensea<\/a> One of me wallets was hacked wtf man <a href=\"https:\/\/t.co\/BbZ4FKtr6h\">pic.twitter.com\/BbZ4FKtr6h<\/a><\/p>&mdash; Waka Flocka (WakaFlocka.eth) (@WakaFlocka) <a href=\"https:\/\/twitter.com\/WakaFlocka\/status\/1475709903184412675?ref_src=twsrc%5Etfw\">December 28, 2021<\/a><\/blockquote><\/div>\n<\/div><\/figure>\n\n\n\n<p class=\"wp-embed-aspect-16-9 wp-has-aspect-ratio wp-block-paragraph\">This is also another method hackers have used to drain peoples wallets, by airdropping an NFT into a persons wallet, and if they choose to sell the NFT or transfer it, the NFT drains the victim&#8217;s wallet.<\/p>\n\n\n\n<p class=\"wp-embed-aspect-16-9 wp-has-aspect-ratio wp-block-paragraph\">The way this works is that initially, the smart contract of the malicious NFT is a wallet draining contract, but it would not have permissions to do anything until the user interacts with it. But once the user interacts with it, then it is going to have the permissions to interact with the users wallet, and then draining it. <\/p>\n\n\n\n<p class=\"wp-embed-aspect-16-9 wp-has-aspect-ratio wp-block-paragraph\">If you receive an airdropped NFT that you do not trust, NFT traders advice that you just hide it, where it is still in the wallet, but it is not on your main page.<\/p>\n\n\n\n<h3 class=\"wp-embed-aspect-16-9 wp-has-aspect-ratio wp-block-heading\">Conclusion<\/h3>\n\n\n\n<p class=\"wp-embed-aspect-16-9 wp-has-aspect-ratio wp-block-paragraph\">As you can see from the methods used above, even if you are using a &#8220;Web3&#8221; platform, you can still fall victim to different cyberattacks, and the ways to protect yourself from such attacks are similar to the &#8220;Old internet&#8221; solutions such as:<\/p>\n\n\n\n<ul type=\"video\" class=\"wp-embed-aspect-16-9 wp-has-aspect-ratio wp-block-list\"><li>Do not click on suspicious links<\/li><li>Only give permissions to systems that you trust <\/li><li>If you do not trust something, test it in an isolated environment, in this case a &#8220;burner wallet&#8221;<\/li><li>If something feels too good to be true, then it probably is.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Sources:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"> <a href=\"https:\/\/theopendao.medium.com\/opensea-phishing-attack-19-february-2022-and-the-opendaos-response-4f71aa80578c\">https:\/\/theopendao.medium.com\/opensea-phishing-attack-19-february-2022-and-the-opendaos-response-4f71aa80578c<\/a><\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-wp-embed is-provider-blockworks wp-block-embed-blockworks\"><div class=\"wp-block-embed__wrapper\">\nhttps:\/\/blockworks.co\/opensea-scammers-went-phishing-and-caught-over-250-nfts-from-17-users\/\n<\/div><\/figure>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe title=\"Crypto Airdrop Wallet Draining Tokens And NFTs\" width=\"640\" height=\"360\" data-src=\"https:\/\/www.youtube.com\/embed\/TIyNE_QASh8?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" class=\"lazyload\" data-load-mode=\"1\"><\/iframe>\n<\/div><figcaption>Crypto airdrop wallet scams<\/figcaption><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>With the NFT market being worth more than $10 billion, it has definitely gained the attention of a lot of people. From NFTs being talked about on the news, to celebrities, public figures and giant companies supporting or even starting NFT projects, it would make sense why hackers and malicious actors have decided to exploit &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/2022\/03\/18\/all-my-apes-gone\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;All My Apes Gone&#8221;<\/span><\/a><\/p>\n","protected":false},"author":382,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[15],"tags":[],"class_list":["post-2702","post","type-post","status-publish","format-standard","hentry","category-cpsc-329-602-w22","entry"],"featured_image_src":null,"featured_image_src_square":null,"author_info":{"display_name":"Umar Hassan","author_link":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/author\/umar-hassan\/"},"_links":{"self":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/2702","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/users\/382"}],"replies":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/comments?post=2702"}],"version-history":[{"count":6,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/2702\/revisions"}],"predecessor-version":[{"id":2710,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/2702\/revisions\/2710"}],"wp:attachment":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/media?parent=2702"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/categories?post=2702"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/tags?post=2702"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}