你的NFT还安全吗?OpenSea“钓鱼攻击”事件又给我们哪些启示?

成都链安Publicado em 2022-02-24Última atualização em 2022-03-03

Resumo

黑客虎视眈眈,用户资产频繁被盗,这都凸显了这个尚未受到监管的NFT交易市场的风险所在。在安全之路上,NFT要走的道路还很远。

2月20日,成都链安链必应-区块链安全态势感知平台舆情监测显示,全球最大的加密数字藏品市场 OpenSea 遭遇了黑客攻击。
根据OpenSea官方的回复,本次事件由黑客趁着 OpenSea 合约升级之时,给所有用户的邮箱发送了一封钓鱼邮件,而不少用户错把其当作官方邮件而将自己的钱包授权,进而导致钱包被盗,目前OpenSea 已经排除了合约迁移工具是攻击载体的可能性。 OpenSea 的联合创始人兼首席执行官 Devin Finzer 发推说攻击者窃取了价值 170 万美元的以太币。

br




「钓鱼攻击」,在互联网世界摸爬滚打的你肯定不陌生,在区块链领域里,这种古老的攻击的方式仍然存在,并蔓延到了NFT资产领域。你的NFT还安全吗?OpenSea“钓鱼攻击”事件又给我们哪些启示?

1 NFT资产被盗事件为何仍有发生
先是去年3月17日,NFT交易市场Nifty Gateway的数名用户遭遇了账号被盗,有受害者称,黑客从其帐户中窃取了价值数千美元的数字艺术品;其他被黑客入侵的用户称,他们存档的信用卡被用来购买额外的NFT。
而在今年1月10日,纽约艺术品藏家兼画廊主托德·克拉默(Todd Kramer)曾发文寻求帮助,他有超过220万美元的NFT艺术品被盗,引发关注。随后,NFT交易平台OpenSea通过阻止对该系列作品的进一步交易来施加干预。
接着2月1日,一位NFT收藏大户larrylawliet.eth在社交媒体表示,其持有的多只无聊猿猴游艇俱乐部(Bored Ape Yacht Club)、变异猿猴游艇俱乐部(Mutant Ape Yacht Club)以及Doodles NFT等系列价值不菲的NFT藏品被黑客盗取。该收藏大户表示,造成本次失窃的直接原因是自己钱包的隐私信息泄漏。
可见随着部分NFT的收藏价值越来越高,黑客也开始觊觎用户的钱包,将用户的NFT洗劫一空,这也是NFT资产被盗事件时常发生的原因。

br



2 你的NFT够安全吗?
当谈到 NFT 智能合约本身的安全性时,事实证明它们能够更好地抵御攻击,因为NFT 智能合约通常比可替代代币的智能合约包含更简单的代码。此外,NFT 生态系统不像 DeFi 那样复杂,这也将黑客威胁降至最低。
目前NFT的风险可大致分为两类:
一是NFT本身的授权问题(NFT持有者可授权其它地址作为代理人),可能因NFT持有者的误操作,导致NFT权限被劫持(主要是钓鱼网站、钱包层面的不安全接口调用);
二是NFT参与DEFI系统后引入的外部风险,如:NFT质押挖矿合约本身所带来的安全风险,这部分与常规DEFI风险基本一致。

br




3 如何保护自己的NFT?

NFT这波热潮吸引了无数人,当然,除了警惕NFT炒作之外,还需要防范各类NFT骗局套路,最近一年与NFT有关的诈骗数量和范围也呈现出现爆炸性增长,大家还需要多加防范。小心钓鱼陷阱、过度包装诈骗、社交媒体诈骗、赠品/空投骗局等等。

br




1、钓鱼陷阱/伪造NFT平台
骗子复制当红NFT零售网站,这些网站看起来与原始网站完全一样,这类网站会获取用户的账号和银行卡信息,进而形成诈骗。当然,还有一些所谓的NFT商店,就是一个空壳,他们在商店中向用户出售根本不存在的产品。


2、假冒艺术家发售NFT骗局
有些项目方因为没有得到艺术家或者明星的授权,比如名画或者歌曲,他们就假冒艺术家,伪造假的NFT,用户需要谨慎购买或出价,因为没有授权的NFT,其实也没有收藏价值,是不被认可的。


3、社交媒体骗局
诈骗分子在加密社区或者社交媒体推特、Telegram、微信群、QQ群等实施诈骗行为,比如他们会假扮客服,或者通过回答你的问题来获取信任,最后再来套路你。


4、赠品/空投骗局
虚假NFT就是冒牌,假限量真增发。由于NFT的内容载体是公开的,伪造基本是没有成本的,导致造假者不断。此外,骗子们大范围免费空投NFT,诱骗数字钱包授权或私钥,趁机窃取用户资产。

br



4 写在最后
黑客虎视眈眈,用户资产频繁被盗,这都凸显了这个尚未受到监管的NFT交易市场的风险所在。在安全之路上,NFT要走的道路还很远。

Leituras Relacionadas

One-Third of arXiv 'Contaminated', 65% of CS Papers Smell of AI, Only 0.7% in Math

Approximately one-third of recently posted arXiv papers show signs of significant AI-generated text, according to a new study. An analysis of 12,750 papers from January 2023 to July 2026 across ten disciplines found a sharp increase in AI text markers following ChatGPT's release, with the overall detection rate reaching 32% in the latest quarter and peaking near 39% in early 2026. The rate varies drastically by field. Computer Science papers lead at 65%, followed by Quantitative Biology (56.3%) and Electrical Engineering (51.3%). Mathematics, however, has the lowest detection rate at just 0.7%. The study's authors note this could be due to mathematicians using AI less or because the detector struggles with the high volume of formulas and symbolic notation in math papers, leaving the true cause unclear. The research highlights that the detector identifies a statistical "AI style" in the text rather than proving full AI authorship. It cannot distinguish between light AI-assisted editing and fully AI-generated content. Furthermore, the detector can produce false positives, as some pre-ChatGPT academic writing also exhibits patterns now flagged as "AI-like." The growing use of AI, particularly in highly competitive fields, is creating a cycle where researchers may feel pressured to adopt AI tools to keep pace. The findings raise questions about the changing nature of academic writing and the emergence of a new "AI style" that is increasingly difficult to distinguish from human prose, potentially undermining trust in written text regardless of its true origin.

marsbitHá 1m

One-Third of arXiv 'Contaminated', 65% of CS Papers Smell of AI, Only 0.7% in Math

marsbitHá 1m

The Biggest Enemy of the AI Bull Market Is Not a Bubble, But the Bond Market?

The bond market is emerging as the most dangerous variable for the AI stock rally. US Bank's chief investment strategist Michael Hartnett warns that surging bond yields are tightening financial conditions beyond what corporate earnings can support. Key indicators include the 30-year Treasury yield hitting 5.2% (a high since 2007) and real yields reaching 3% (a peak since 2008). Hartnett argues this bond market stress could force the Fed to hike rates, which would be detrimental to equities. A critical risk signal would be if the bullish combination of "rising yields & rising bank stocks" flips to "rising yields & falling bank stocks," potentially triggering a broader de-risking in markets. Simultaneously, credit risk for hyperscale cloud companies has reached record highs, with Credit Default Swaps (CDS) at unprecedented levels. This reflects bond investors' growing skepticism about the return on investment from the massive AI capital expenditure boom. The core concern is: if debt markets refuse to fund the AI spending spree, where will the capital for expensive memory chips and potentially unprofitable frontier models come from? Hartnett frames the current dynamic as "FCI > EPS" – where tightening Financial Conditions outweigh the support from Earnings Per Share. He advises a defensive tilt: going long defensive stocks, high-dividend stocks, and long-duration bonds, while shorting bank stocks, brokers, tech, and industrials to hedge against a potential reversal of the "boom" narrative. From a macro perspective, the 2020s are characterized by supply-side constraints (labor, imports, oil) rather than demand, while bond and equity supply remains abundant due to persistent fiscal deficits and reduced corporate buybacks. In this environment, Hartnett sees gold and Bitcoin quietly forming a base in 2026.

marsbitHá 3m

The Biggest Enemy of the AI Bull Market Is Not a Bubble, But the Bond Market?

marsbitHá 3m

"Injective Nova Program" Final Demo Day Summit Finals Successfully Concluded: TOP3 Teams Announced, Co-creating a New Paradigm of AI × Web3

"Injective Nova Program" Final Demo Day Successfully Concludes in Hangzhou: Top 3 Teams Announced, Shaping the New Paradigm of AI × Web3 On July 25, 2026, the Final Demo Day of the "Injective Nova Program," jointly launched by Injective, Microsoft, and Web3Labs, was successfully held in Hangzhou. The event gathered global blockchain experts, AI developers, top VC representatives, and ecosystem partners to witness innovations at the intersection of AI and decentralized networks. The program generated significant global interest, receiving 89 applications from over 10 countries and achieving over 1,000,000 ecosystem impressions. After a rigorous review, a global Top 10 was announced on July 10. These teams participated in an exclusive visit to Microsoft's Beijing headquarters for deep technical exchanges on July 16. At the final demo day, the Top 10 teams delivered live presentations. The jury evaluated projects based on technological innovation, commercial potential, and synergy with the Injective ecosystem, ultimately awarding the top three positions. All winning and shortlisted projects will receive comprehensive incubation support, technical resources, and capital access from Injective, Microsoft, and Web3Labs. The successful conclusion of the Final Demo Day marks a significant milestone for the first phase of the Injective Nova Program. The organizers plan to continue supporting global builders and exploring the limitless possibilities of AI and decentralized technology integration.

marsbitHá 9m

"Injective Nova Program" Final Demo Day Summit Finals Successfully Concluded: TOP3 Teams Announced, Co-creating a New Paradigm of AI × Web3

marsbitHá 9m

Trading

Spot
活动图片