Possible significant OpenSea exploit; high value NFTs stolen
etherscan.io
etherscan.io
Etherscan and revoke.cash are down. This is the web3 utopia hype they have been screaming about yet the centralized services they use (Etherscan) are going down, NFTs being stolen via a vulnerability in OpenSea and there is no way to get them back. Ha.
What a magnificent disaster.
Can’t help but wonder… in the midst of the panic, are they even checking what these revoke websites contracts do? It’s too easy to social engineer something like this…
People are like 'well yeah obviously' but no, not obviously in everyway to everyone. And the statistics will not save you when someone finds the next oopsie that can steal your investment, and there will always be a next one. Neither will any institutions.
Example attacker transaction: https://ethtx.info/mainnet/0x18c0b67adf306b7f0da948e238c1397...
We see that this tx performs 3 layers of delegation, whereas normally the opensea WyvernExchange contract needs 2 (user's proxy delegates action to WyvernAtomicizer, which performs the transfer.) In this case there's another layer: user proxy delegates to attacker contract 0xa2c0946ad444dccf990394c5cbe019a858a945bd, which then calls the Atomicizer to do a malicious transfer.
The regulator has already intervened to force changes in banks (no more links in messages, shared liability, protective measures, authenticated SMS) and Telcos (SMS ID registry)
So yes, in the financial world, in properly run countries, systemic issues are addressed by regulatory systems. Because losing an email is one things, losing your live savings is another.
Crypto either will end up fully regulated or die