你的NFT还安全吗?OpenSea“钓鱼攻击”事件又给我们哪些启示?

成都链安Published on 2022-02-24Last updated on 2022-03-03

Abstract

黑客虎视眈眈,用户资产频繁被盗,这都凸显了这个尚未受到监管的NFT交易市场的风险所在。在安全之路上,NFT要走的道路还很远。

2月20日,成都链安链必应-区块链安全态势感知平台舆情监测显示,全球最大的加密数字藏品市场 OpenSea 遭遇了黑客攻击。
根据OpenSea官方的回复,本次事件由黑客趁着 OpenSea 合约升级之时,给所有用户的邮箱发送了一封钓鱼邮件,而不少用户错把其当作官方邮件而将自己的钱包授权,进而导致钱包被盗,目前OpenSea 已经排除了合约迁移工具是攻击载体的可能性。 OpenSea 的联合创始人兼首席执行官 Devin Finzer 发推说攻击者窃取了价值 170 万美元的以太币。

br




「钓鱼攻击」,在互联网世界摸爬滚打的你肯定不陌生,在区块链领域里,这种古老的攻击的方式仍然存在,并蔓延到了NFT资产领域。你的NFT还安全吗?OpenSea“钓鱼攻击”事件又给我们哪些启示?

1 NFT资产被盗事件为何仍有发生
先是去年3月17日,NFT交易市场Nifty Gateway的数名用户遭遇了账号被盗,有受害者称,黑客从其帐户中窃取了价值数千美元的数字艺术品;其他被黑客入侵的用户称,他们存档的信用卡被用来购买额外的NFT。
而在今年1月10日,纽约艺术品藏家兼画廊主托德·克拉默(Todd Kramer)曾发文寻求帮助,他有超过220万美元的NFT艺术品被盗,引发关注。随后,NFT交易平台OpenSea通过阻止对该系列作品的进一步交易来施加干预。
接着2月1日,一位NFT收藏大户larrylawliet.eth在社交媒体表示,其持有的多只无聊猿猴游艇俱乐部(Bored Ape Yacht Club)、变异猿猴游艇俱乐部(Mutant Ape Yacht Club)以及Doodles NFT等系列价值不菲的NFT藏品被黑客盗取。该收藏大户表示,造成本次失窃的直接原因是自己钱包的隐私信息泄漏。
可见随着部分NFT的收藏价值越来越高,黑客也开始觊觎用户的钱包,将用户的NFT洗劫一空,这也是NFT资产被盗事件时常发生的原因。

br



2 你的NFT够安全吗?
当谈到 NFT 智能合约本身的安全性时,事实证明它们能够更好地抵御攻击,因为NFT 智能合约通常比可替代代币的智能合约包含更简单的代码。此外,NFT 生态系统不像 DeFi 那样复杂,这也将黑客威胁降至最低。
目前NFT的风险可大致分为两类:
一是NFT本身的授权问题(NFT持有者可授权其它地址作为代理人),可能因NFT持有者的误操作,导致NFT权限被劫持(主要是钓鱼网站、钱包层面的不安全接口调用);
二是NFT参与DEFI系统后引入的外部风险,如:NFT质押挖矿合约本身所带来的安全风险,这部分与常规DEFI风险基本一致。

br




3 如何保护自己的NFT?

NFT这波热潮吸引了无数人,当然,除了警惕NFT炒作之外,还需要防范各类NFT骗局套路,最近一年与NFT有关的诈骗数量和范围也呈现出现爆炸性增长,大家还需要多加防范。小心钓鱼陷阱、过度包装诈骗、社交媒体诈骗、赠品/空投骗局等等。

br




1、钓鱼陷阱/伪造NFT平台
骗子复制当红NFT零售网站,这些网站看起来与原始网站完全一样,这类网站会获取用户的账号和银行卡信息,进而形成诈骗。当然,还有一些所谓的NFT商店,就是一个空壳,他们在商店中向用户出售根本不存在的产品。


2、假冒艺术家发售NFT骗局
有些项目方因为没有得到艺术家或者明星的授权,比如名画或者歌曲,他们就假冒艺术家,伪造假的NFT,用户需要谨慎购买或出价,因为没有授权的NFT,其实也没有收藏价值,是不被认可的。


3、社交媒体骗局
诈骗分子在加密社区或者社交媒体推特、Telegram、微信群、QQ群等实施诈骗行为,比如他们会假扮客服,或者通过回答你的问题来获取信任,最后再来套路你。


4、赠品/空投骗局
虚假NFT就是冒牌,假限量真增发。由于NFT的内容载体是公开的,伪造基本是没有成本的,导致造假者不断。此外,骗子们大范围免费空投NFT,诱骗数字钱包授权或私钥,趁机窃取用户资产。

br



4 写在最后
黑客虎视眈眈,用户资产频繁被盗,这都凸显了这个尚未受到监管的NFT交易市场的风险所在。在安全之路上,NFT要走的道路还很远。

Related Reads

Institutions and On-Chain Capital Are Bullish on CXMT's Continued Surge, Except for South Koreans

Changxin Technology, China's leading memory chip manufacturer, made its debut on the STAR Market, closing up 465.8% with a market cap of 3.28 trillion yuan. Its record-breaking first day included over 140 billion yuan in turnover. Market opinions on its future trajectory diverge. Nomura issued a "buy" rating with a 116 yuan target (implying ~1239.5% upside), citing rapid growth projections, expansion into HBM, and the "crown jewel" status of its DRAM business. Northeast Securities offered a more conservative 10-15x PE valuation range, implying significant but lower upside. While the stock's surge reflects optimism, analysis suggests Changxin's current capacity remains below giants like Samsung and SK Hynix. U.S. equipment export restrictions may limit near-term expansion, and the company is not yet competitive in the high-margin HBM segment crucial for AI. On-chain data from Hyperliquid showed pre-listing positioning was net long by wallets tagged to the U.S., Hong Kong, and mainland China, while Korean-tagged wallets were heavily net short. Other bullish factors noted include a low initial float (6.63%), the ongoing memory "super cycle," and the stock's unique status as a domestic industry leader. Founder Zhu Yiming's plan to distribute 40% of his increased wealth to employees may also slow share sales. Multiple ETF issuers warned that fund net asset values might deviate from displayed reference values on the first day due to the large gap between Changxin's IPO price and its market price.

Odaily星球日报4m ago

Institutions and On-Chain Capital Are Bullish on CXMT's Continued Surge, Except for South Koreans

Odaily星球日报4m ago

Claude Code Slashes 80% of Prompt Tokens, But Opus 5 Just Adds Them Right Back In

Claude Code, the AI coding assistant from Anthropic, recently announced a massive reduction of over 80% in its system prompt content for models like Opus 5 and Fable 5. The goal was to remove verbose, often conflicting, rules (like strict commenting and documentation requirements) and replace them with a simpler directive: write code that matches the style of the surrounding project. This "pruning" aims to make the model more efficient by reducing internal conflict from overlapping instructions, with no measurable performance drop reported. However, a developer's (@chenchengpro) investigation revealed a twist. While the prompt was drastically cut from 15,225 characters in Opus 4.7 to 4,467 in Opus 4.8, it *increased* by approximately 72% to 7,694 characters in Opus 5. This isn't a contradiction. The "over 80% cut" refers to the overall shift from the old, detailed rulebook-style prompts to a new, streamlined system. The 72% increase for Opus 5 represents new, targeted instructions added to manage the model's enhanced capabilities. Opus 5 is more proactive—it likes to report progress, generate longer outputs, use sub-agents, and expand task scope. The added prompt content (roughly 3,755 characters) primarily provides guidelines for "Delivering work" (controlling task scope, progress reporting) and "Corrections" (limiting excessive self-correction). These new rules are necessary to curb potential over-engineering on simple tasks, ensuring efficiency even as the model becomes more independent. In short, the old, restrictive manual was deleted, but new guidelines were written to harness the model's newfound initiative.

marsbit9m ago

Claude Code Slashes 80% of Prompt Tokens, But Opus 5 Just Adds Them Right Back In

marsbit9m ago

One-Third of arXiv 'Contaminated', 65% of CS Papers Smell of AI, Only 0.7% in Math

Approximately one-third of recently posted arXiv papers show signs of significant AI-generated text, according to a new study. An analysis of 12,750 papers from January 2023 to July 2026 across ten disciplines found a sharp increase in AI text markers following ChatGPT's release, with the overall detection rate reaching 32% in the latest quarter and peaking near 39% in early 2026. The rate varies drastically by field. Computer Science papers lead at 65%, followed by Quantitative Biology (56.3%) and Electrical Engineering (51.3%). Mathematics, however, has the lowest detection rate at just 0.7%. The study's authors note this could be due to mathematicians using AI less or because the detector struggles with the high volume of formulas and symbolic notation in math papers, leaving the true cause unclear. The research highlights that the detector identifies a statistical "AI style" in the text rather than proving full AI authorship. It cannot distinguish between light AI-assisted editing and fully AI-generated content. Furthermore, the detector can produce false positives, as some pre-ChatGPT academic writing also exhibits patterns now flagged as "AI-like." The growing use of AI, particularly in highly competitive fields, is creating a cycle where researchers may feel pressured to adopt AI tools to keep pace. The findings raise questions about the changing nature of academic writing and the emergence of a new "AI style" that is increasingly difficult to distinguish from human prose, potentially undermining trust in written text regardless of its true origin.

marsbit12m ago

One-Third of arXiv 'Contaminated', 65% of CS Papers Smell of AI, Only 0.7% in Math

marsbit12m ago

The Biggest Enemy of the AI Bull Market Is Not a Bubble, But the Bond Market?

The bond market is emerging as the most dangerous variable for the AI stock rally. US Bank's chief investment strategist Michael Hartnett warns that surging bond yields are tightening financial conditions beyond what corporate earnings can support. Key indicators include the 30-year Treasury yield hitting 5.2% (a high since 2007) and real yields reaching 3% (a peak since 2008). Hartnett argues this bond market stress could force the Fed to hike rates, which would be detrimental to equities. A critical risk signal would be if the bullish combination of "rising yields & rising bank stocks" flips to "rising yields & falling bank stocks," potentially triggering a broader de-risking in markets. Simultaneously, credit risk for hyperscale cloud companies has reached record highs, with Credit Default Swaps (CDS) at unprecedented levels. This reflects bond investors' growing skepticism about the return on investment from the massive AI capital expenditure boom. The core concern is: if debt markets refuse to fund the AI spending spree, where will the capital for expensive memory chips and potentially unprofitable frontier models come from? Hartnett frames the current dynamic as "FCI > EPS" – where tightening Financial Conditions outweigh the support from Earnings Per Share. He advises a defensive tilt: going long defensive stocks, high-dividend stocks, and long-duration bonds, while shorting bank stocks, brokers, tech, and industrials to hedge against a potential reversal of the "boom" narrative. From a macro perspective, the 2020s are characterized by supply-side constraints (labor, imports, oil) rather than demand, while bond and equity supply remains abundant due to persistent fiscal deficits and reduced corporate buybacks. In this environment, Hartnett sees gold and Bitcoin quietly forming a base in 2026.

marsbit14m ago

The Biggest Enemy of the AI Bull Market Is Not a Bubble, But the Bond Market?

marsbit14m ago

Trading

Spot
活动图片