• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Saturday, September 13, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

Top NFT Scams And Hacks To Avoid

11 March 2022
in NFT
Reading Time: 4 mins read
A A
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT

Related articles

SEC became a defendant in the NFT classification lawsuit

SEC became a defendant in the NFT classification lawsuit

30 July 2024
DraftKings Dumps NFT Business, Citing Legal Developments

DraftKings Dumps NFT Business, Citing Legal Developments

30 July 2024
Cryptohopper
ADVERTISEMENT

By Mitchell Amador

NFTs exploded into the public consciousness following the artist Beeple’s iconic sale of “Everydays – The First 5000 Days” for a whopping $69 million. This NFT also had the distinction of being the first purely digital work of art ever offered by Christie’s, a major auction house.

With social media behemoths like Twitter integrating NFTs into their app and Meta building stealth apps to accelerate mainstream adoption, the integration of  NFTs into everyday life seems imminent. A Google Trends analysis of the term NFT shows as much.  

However, a large number of users remain totally unaware of the security concerns surrounding NFTs. Education on these concerns is more important than ever.

Here are a few attack vectors to watch out for, which are a mixture of attacks against platforms and attacks against users.  

NFTs that Log your IP 

Some NFTs displayed on OpenSea can log your IP address and other user agent data, such as browser, operating system, etc. As explained by Bax of Convex Labs, this issue is a result of OpenSea allowing NFT sellers to add an “animation_url” to the NFT’s metadata. The animation_url field supports HTML, and as demonstrated by Bax, the injected code from the data-grabbing NFT can include commonly-used IP harvesting code from a site called IPlogger.org. Users can mitigate this through blocking scripts (although that will cause the NFT not to render) and using a VPN for their internet browsing.

The flexibility of NFT metadata, which is part of why NFTs are such a fertile new artistic medium, allows arbitrary code to render the NFT in the user’s browser. This flexibility creates great risks beyond just NFTs that can log your IP.

Smart Contract Flaws

In 2017, CryptoPunks, one of the most popular NFT projects, suffered from a smart contract flaw that blocked (CRYPTO: ETH) from being sent to the seller’s wallet. Attackers could use this flaw to buy CryptoPunks NFTs and then withdraw the money from the contract. Due to the devastating bug, CryptoPunks had to start over and relaunch its project with a new smart contract. Unfortunately, by the time the bug had been discovered, all 10,000 CryptoPunks were in circulation.

In August 2021, whitehat samczsun discovered a vulnerability in the NFT project Hashmask. Specifically, there was a bug in the function used to mint new NFTs that would have allowed a malicious attacker to mint more than 16,384 Hashmasks. Fortunately, the bug was not exploited, and Hashmask paid samczsun a $12,500 bug bounty for his disclosure.

Another interesting case that showcases potential NFT problems is the Meebit hack from May 2021. The attacker exploited the fact that the metadata of the next Meebit to be minted was available right before minting. The attacker was able to “reroll” the Meebit mint before it occurred to get a more favorable Meebit. This shows how important random number generation (RNG) is on the blockchain, and how hard it is to get it right. Whenever projects rely on randomized bits for their NFT, it’s worth checking how they approach RNG. Using an off-chain, verifiable randomness oracle, like Chainlink’s VRF, is the right way to go.

Account Hijacking 

Crypto Twitter was recently abuzz with reports of user wallets’ being drained after receiving a certain free NFT. Check Point Research, a cybersecurity firm, got in touch with the affected users and discovered a significant vulnerability in OpenSea which was being exploited by attackers to hijack a user’s account and wallet.

Here’s how it was done: Hackers created malicious NFTs and presented them to the target. After the users viewed the malicious NFT, the OpenSea storage domain triggered a pop-up window (very innocuous and common). If the victim clicked “connect wallet”, the hacker obtained access to the victim’s wallet. 

Hackers could then steal the assets in the user’s wallet by obtaining further approvals. 

OpenSea quickly developed a fix after the vulnerability was disclosed. According to OpenSea, the attackers relied on users signing off on harmful transactions using third-party wallets. 

In March of last year, multiple customers of Nifty Gateway, an NFT trading exchange, had their accounts stolen. Some victims claimed that hackers stole thousands of dollars’ worth of digital art from their accounts, while others claimed that their accounts were hacked for no reason at all. 

The accounts that were hacked, it turned out, did not enable two-factor authentication (2FA). Enabling 2FA is crucial, and enabling 2FA via an authenticator app sidesteps SIM swapping.

But even if platforms adopt the latest security measures, a substantial risk is associated with users’ failure to securely store their passwords and other sensitive data, which unscrupulous actors can use to acquire their NFTs. 

To keep your passwords safe, use a password manager. 

Impersonation and Permanence 

The possibility of purchasing fraudulent NFTs also poses a serious danger. Malicious actors may pose as well-known creators and sell forged ownership certificates. For example, this summer, a well-known collector & NFT artist known as ‘Pranksy’ purchased a fake Banksy NFT for $300,000. Luckily, the scammer returned Pranksy’s funds. Not everyone who gets scammed in the future will be so fortunate. 

Additionally, if the NFT points to an image or music file on, say, Amazon Web Services, it’s possible that that file can be swapped later for some other file, or even deleted. It is good practice that NFTs point to resources on IPFS, a decentralized file system, to avoid them easily being swapped to something else by whoever has easy access to some centralized server. If the metadata isn’t decentralized, the NFT isn’t decentralized. 

NFTs now represent a lucrative frontier for the same blackhat hackers who pose a threat to smart contracts, and it is critical for security research firms to focus on this burgeoning sector of Web3.

There’s not much you can do if a platform you use suffers a smart contract or web breach, but there are some things you can do to protect yourself as a user: use a VPN, use 2FA to protect your login credentials, store your passwords in a password manager, and be aware of possible impersonations and phishing attacks. In crypto, it’s always a good idea to be skeptical because wherever there are high-value assets, you can be sure that scammers, hackers, and other bad actors will follow. 

Author’s Bio:

Mitchell Amador, CEO and Founder of Immunefi, a bug bounty and security service.

 

Credit: Source link

[crypto-donation-box]
Tags: AvoidHacksNFTScamsTop
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

Crypto bull phase could start in 10 days

Next Post

Now You Can Try ‘Teleporting’ Bitcoin for Greater Privacy With CoinSwaps

Related Posts

SEC became a defendant in the NFT classification lawsuit

SEC became a defendant in the NFT classification lawsuit

30 July 2024
0

Law professor and filmmaker Brian Frye and songwriter Jonathon Mann have filed a lawsuit against the U.S. Securities and Exchange...

DraftKings Dumps NFT Business, Citing Legal Developments

DraftKings Dumps NFT Business, Citing Legal Developments

30 July 2024
0

Sports gambling company Draftkings is shutting down its non-fungible token (NFT) business "effective immediately," the company said in an email...

Empire Newsletter: Why the Song-a-Day man is suing the SEC

Empire Newsletter: Why the Song-a-Day man is suing the SEC

30 July 2024
0

Today, enjoy the Empire newsletter on Blockworks.co. Tomorrow, get the news delivered directly to your inbox. Subscribe to the Empire newsletter....

Two artists sue the SEC for regulation on NFTs

Two artists sue the SEC for regulation on NFTs

30 July 2024
0

Still confusion in the field of regulation in the USA: two artists have sued the SEC, drawing a comparison between...

BlockDAG Soars Over Solana Bullish Surge, Polkadot Price

BlockDAG Soars Over Solana Bullish Surge, Polkadot Price

29 July 2024
0

The crypto market opens with optimistic trends of Solana’s bullish surge and Polkadot price increase. As investors focus on Solana’s...

Load More
Next Post

Now You Can Try 'Teleporting' Bitcoin for Greater Privacy With CoinSwaps

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
Ethereum Staking, XRP, And Dogecoin ETFs All Pushed Back By SEC, Here Are The Next Important Dates

Ethereum Staking, XRP, And Dogecoin ETFs All Pushed Back By SEC, Here Are The Next Important Dates

13 September 2025
Bitcoin News Today, Solana Price Prediction & Where Could You Turn ,000 Into ,000 In September – Mitrade

Bitcoin News Today, Solana Price Prediction & Where Could You Turn $1,000 Into $15,000 In September – Mitrade

13 September 2025
Crypto News Today (Sept. 12): BTC, ETH, XRP, BNB, SOL, DOGE, ADA, LINK, SUI – Binance

Crypto News Today (Sept. 12): BTC, ETH, XRP, BNB, SOL, DOGE, ADA, LINK, SUI – Binance

13 September 2025
Want an Easy Way to Use Crypto? This Undervalued Altcoin Might Be It

Want an Easy Way to Use Crypto? This Undervalued Altcoin Might Be It

13 September 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • Ethereum Staking, XRP, And Dogecoin ETFs All Pushed Back By SEC, Here Are The Next Important Dates
  • Bitcoin News Today, Solana Price Prediction & Where Could You Turn $1,000 Into $15,000 In September – Mitrade
  • Crypto News Today (Sept. 12): BTC, ETH, XRP, BNB, SOL, DOGE, ADA, LINK, SUI – Binance
  • Want an Easy Way to Use Crypto? This Undervalued Altcoin Might Be It
  • While Solana Moves And BNB Accelerates, Pepeto Stands Out Boldly As The Best Crypto To Buy Now – CoinCentral

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 115,895.00
  • ethereumEthereum (ETH) $ 4,697.36
  • xrpXRP (XRP) $ 3.15
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 937.63
  • solanaSolana (SOL) $ 240.04
  • usd-coinUSDC (USDC) $ 0.999797
  • dogecoinDogecoin (DOGE) $ 0.297253
  • staked-etherLido Staked Ether (STETH) $ 4,684.87
  • cardanoCardano (ADA) $ 0.941062
  • tronTRON (TRX) $ 0.351069
  • wrapped-stethWrapped stETH (WSTETH) $ 5,688.72
  • chainlinkChainlink (LINK) $ 24.99
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 5,063.15
  • hyperliquidHyperliquid (HYPE) $ 55.98
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 115,730.00
  • suiSui (SUI) $ 3.81
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • stellarStellar (XLM) $ 0.409127
  • avalanche-2Avalanche (AVAX) $ 29.88
  • wrapped-eethWrapped eETH (WEETH) $ 5,042.51
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.01
  • bitcoin-cashBitcoin Cash (BCH) $ 600.87
  • wethWETH (WETH) $ 4,695.22
  • hedera-hashgraphHedera (HBAR) $ 0.250790
  • litecoinLitecoin (LTC) $ 119.82
  • leo-tokenLEO Token (LEO) $ 9.57
  • shiba-inuShiba Inu (SHIB) $ 0.000014
  • crypto-com-chainCronos (CRO) $ 0.252859
  • the-open-networkToncoin (TON) $ 3.23
  • usdsUSDS (USDS) $ 0.999686
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 115,880.00
  • polkadotPolkadot (DOT) $ 4.55
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • whitebitWhiteBIT Coin (WBT) $ 44.29
  • uniswapUniswap (UNI) $ 10.18
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.213420
  • mantleMantle (MNT) $ 1.71
  • moneroMonero (XMR) $ 286.10
  • ethenaEthena (ENA) $ 0.761070
  • pepePepe (PEPE) $ 0.000012
  • aaveAave (AAVE) $ 316.60
  • bitget-tokenBitget Token (BGB) $ 5.03
  • daiDai (DAI) $ 1.00
  • okbOKB (OKB) $ 201.99
  • memecoreMemeCore (M) $ 2.41
  • nearNEAR Protocol (NEAR) $ 2.84
  • jito-staked-solJito Staked SOL (JITOSOL) $ 295.18
  • bittensorBittensor (TAO) $ 363.77