In Latest OpenSea Exploit, Hackers Target NFT Owners on Discord

A phishing attack on OpenSea’s Discord server led some users to click scam links

article-image

Source: Shutterstock

share

key takeaways

  • OpenSea’s marketplace was not directly affected
  • The scam website was not very sophisticated and losses appear to be minimal

The OpenSea Discord server was compromised by scammers early Friday, according to chat records. 

Fake announcements about a partnership with YouTube directed OpenSea community members to a phishing website as scammers sought to trick NFT connoisseurs into minting a new NFT (non-fungible token) series that doesn’t actually exist. Instead, transactions on the suspect site authorized the transfer of NFTs from users’ wallets.

OpenSea confirmed the reports via their official Twitter support account.

Loading Tweet..

The scam messages pointed users to a suspicious website, YouTubeNFT.art, which according to domain records, was registered today with discount domain registrar NameCheap.

Members of the OpenSea Discord community quickly sounded the alarm, and moderators removed the offending announcement channel, as well as a compromised chatbot — but not before some users were taken by the scam.

An apparent vulnerability in the server’s webhooks connection was to blame, according to community members, who also identified the wallet address receiving stolen NFTs. About $20,000 worth of NFTs were transferred to the wallet as of 10:00 am ET, indicating the damage was limited.

OpenSea said fewer than 10 community members were affected.

Loading Tweet..

Other recent attempts to steal NFTs from unsuspecting users have been more successful, including one last month which targeted Bored Ape Yacht Club NFT holders and managed to nab $10 million worth of the tokens.


Get the news in your inbox. Explore Blockworks newsletters:

Tags

Decoding crypto and the markets. Daily, with Byron Gilliam.

Upcoming Events

Old Billingsgate

Mon - Wed, October 13 - 15, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

Industry City | Brooklyn, NY

TUES - THURS, JUNE 24 - 26, 2025

Permissionless IV serves as the definitive gathering for crypto’s technical founders, developers, and builders to come together and create the future.If you’re ready to shape the future of crypto, Permissionless IV is where it happens.

Brooklyn, NY

SUN - MON, JUN. 22 - 23, 2025

Blockworks and Cracked Labs are teaming up for the third installment of the Permissionless Hackathon, happening June 22–23, 2025 in Brooklyn, NY. This is a 36-hour IRL builder sprint where developers, designers, and creatives ship real projects solving real problems across […]

recent research

Research Report Templates (8).png

Research

Meta-aggregators like Titan and Kamino Swap improve price execution for users, making the Solana swapping landscape more competitive. Jupiter has incorporated meta-aggregation features into its latest routing engine to keep users on its front end (own the user, own the flow). At large, teams are treating swaps as a commoditized complement, offering incredibly cheap or free swaps to own the end-user and increase demand for high-margin product offerings (multi-product DeFi). On another note, the divergence in the concentration of aggregator volume between DEXs suggests increased specialization at the DEX layer by asset type.

article-image

Inflation ticked up, but less than expected

article-image

OS1 is set to disappear next week, and some traders aren’t happy

article-image

Total stablecoin supply sits at $249 billion

article-image

Why nobody can ever truly “win” Bitcoin mining

article-image

Privy said it would still operate as an “independent product” despite the acquisition

article-image

Franklin Templeton’s Roger Bayston tells Blockworks that stablecoins and market funds ‘complement’ each other