“Scam artists” took advantage of a contract migration initiative to steal NFTs from users in an opportunistic phishing attack.
See also: YouTube: Launches NFTs so fans can "own" videos

Last week, NFT marketplace OpenSea announced the launch of migration contracts and an upgrade to ensure that inactive, old NFT listings on Ethereum expire safely and allow OpenSea to “offer new security features in the future.”.
The contract migration schedule was set from February 18 to February 25.
NFT holders must make the switch, and OpenSea has published a guide to help them. After the deadline, any listings that are not migrated will expire, although they could be relisted after that window without further fees.
However, an attacker saw an opportunity to steal cash. Check Point Research has suggested that phishing emails were sent to users, linking them to fraudulent websites.
According to reports, Marketplace users were asked to click on a link and sign a malicious transaction created to look like a legitimate request from OpenSea.
See also: In the future, stocks and real estate will be converted into NFTs
According to the researchers, the attacker created his contract before the transition and used atomicMatch_, a request format “that can steal all of the victims’ NFTS in a single transaction.”.
The wallet associated with the phishing attack had over $2 million after the sale of some of the stolen NFTs, CPR noted, though at the time of writing, just over $8,000 remained in the account. In total, more than 350 transactions have been made from this wallet address, including deposits and withdrawals.

Initially, it was believed that 32 users had their NFTs stolen after they fell victim to the phishing attack.
In an update, OpenSea said its team is working “around the clock” on the investigation, and that the number of suspected victims has been narrowed down to 17.
It has been over 22 hours since the last fraudulent transaction made in the attacker's wallet.
Nadav Hollander, CTO of OpenSea, posted a thread on Twitter containing the organization's current understanding of the attack, which the company does not believe originated from OpenSea.
Additionally, orders were not executed against the new Wyvern 2.3 contract.
See also: Paris Hilton is "obsessed" with non-fungible tokens (NFTs)
Cybersecurity expert Dan Guido also highlighted the inherent security issues with wallets and their exposure to phishing.
Of course, OpenSea continues its research.
Information source: zdnet.com
