Arthur_0x wrote on Twitter that they had previously only ever used a hardware wallet on their PC, but when they started more regularly trading NFTs they'd started using a hot wallet. "Hot wallet on mobile phone is indeed not safe enough", they wrote on Twitter, "Guess no more hot wallet usage then." They also wrote, "The only thing I can say to the hacker is: you mess with the wrong person" and tweeted the wallet address to which the NFTs were being transferred, asking for it to be blocklisted.
Hacker steals more than $1.5 million after compromising wallets belonging to crypto whale Arthur_0x
- Tweet by Arthur_0x
- Tweet by Arthur_0x
- Attacker wallet on Etherscan
Hacker steals $1.45 million from OneRing Finance using code that self-destructs after the attack
The hacker complicated things somewhat for OneRing by covering their tracks. They used a "self-destruct" mechanism — typically used by developers to destroy smart contracts that are found to have a bug — to destroy the contract they used to carry out the attack, making it more difficult for OneRing to determine which parts of their codebase were vulnerable and led to the attack.
- "OneRing Finance exploit. Post-mortem — After OShare Hack.", OneRing Finance blog
- Tweet thread by PeckShield
NFT scammers take over the Twitter account of a Florida gubernatorial candidate
The Fried account compromise is only one instance of what has become a trend on Twitter: Twitter accounts belonging to high-profile individuals, or accounts that are verified or have a large number of followers, being compromised and sold to NFT scammers. On March 11, ESPN baseball reporter Jeff Passan also had his twitter account compromised and repurposed to shill Skulltoons NFTs. Skulltoons distanced themselves from that incident, writing that they believed the hackers were trying to scam their NFT community.
- "Hackers hijack Nikki Fried’s campaign Twitter account", Florida Politics
People briefly borrow Bored Ape NFTs to claim as much as $1.1 million in $APE tokens
People were somewhat split on whether this could be classed as a vulnerability in the $APE airdrop, since (as with many crypto hacks and scams) the person was operating completely within the rules set out in code.
Australian regulatory agency begins lawsuit against Facebook over failing to address scammy crypto ads
- "ACCC takes action over alleged misleading conduct by Meta for publishing scam celebrity crypto ads on Facebook", Australian Competition & Consumer Commission
Discord hack targeting Rare Bears NFT project nets attacker $800,000
Not only did the attackers post a fake mint link, they took steps to prevent the project from thwarting their attack by banning other members and removing user rights that would have allowed other project members to delete the fake links. They also added a bot to the server that locked channels so people couldn't send warnings that the links were fake.
The Rare Bears team did eventually regain access and secured their Discord server. In an apology posted on their Twitter page, they addressed the multiple security breaches that Rare Bears have faced to date, and said they had "stepped up" and would be having a firm audit their project.
Hundred Finance and Agave Finance are both exploited for a collective $12 million
Hundred and Agave were the second and third defi protocols targeted by flash loan attacks that same day, with Deus Finance losing more than $3 million to hackers using the same class of exploit.
Hackers make off with over $3 million from Deus Finance
Sneaky malware replaces Bitcoin addresses in clipboard to reroute transactions
Discord compromise targets fans of the Wizard Pass project in a two-for-one scam that both accepted payments for fake NFTs and stole the NFTs that victims already owned
A Twitter thread by SerpentAU suggested that the malicious minting website had not only accepted ETH from victims and provided nothing in return, but had also prompted users to grant full access to their NFT wallet, allowing valuable NFTs to be stolen. It's not yet clear how many NFTs were stolen as a result.