OpenSea began investigating reports of stolen non-fungible tokens on February 19, 2022, as Ethereum transactions showed a suspicious contract executing a series of interactions connected to the marketplace’s Wyvern trading system.

The marketplace’s initial public position was deliberately preliminary. OpenSea said it was investigating rumors of an exploit associated with its smart contracts but believed the activity appeared to be a phishing attack originating outside its website. Late on February 19, co-founder and chief executive Devin Finzer said the company did not believe OpenSea’s website was the source and that 32 users had signed a malicious payload, with some NFTs subsequently stolen.

Those were contemporaneous claims from an investigation still in progress, not a completed forensic finding. The number of affected users, the delivery mechanism and the value removed were unresolved when the date ended.

What the chain showed

Ethereum’s public ledger supplies the clearest dated record. Etherscan records interactions with contract address 0xa2c0946aD444DCCf990394C5cBe019a858A945bD beginning at 18:56:58 UTC on February 19. Additional contract calls continued through the evening and into February 20 UTC.

One transaction at 21:57:29 UTC on February 19 invoked the contract later associated with the campaign. Independent technical analysis published during the incident found that the contract could submit previously signed order data to the Wyvern Exchange’s `atomicMatch_` function. In the analyzed transaction, NFTs moved from a user to the other side of the order for zero ether.

The ledger verifies transaction times, addresses, contract calls and token movements. It does not, by itself, reveal how signatures were obtained, identify the person controlling an address or establish whether OpenSea’s own systems were compromised. Etherscan’s later-added phishing labels are also annotations, not facts encoded when the transactions were confirmed.

Why the timing mattered

OpenSea was moving listings to a replacement contract and had asked users to migrate active Ethereum listings. That operational change created a credible theme for impersonation: a fraudulent page could imitate the migration process and ask a wallet holder to sign data whose actual effect differed from the interface’s presentation.

The incident therefore exposed a boundary in wallet-based markets. Ethereum could execute exactly what a valid signature authorized while the signer remained mistaken about the authorization’s meaning. Control of an NFT did not require compromising Ethereum’s consensus rules or extracting a private key if an attacker could obtain a usable order signature through deception.

That distinction mattered institutionally because OpenSea was a central interface for a market whose settlement occurred through user-controlled wallets and public contracts. A campaign originating away from the marketplace could still exploit its branding, workflows and trading infrastructure. Responsibility was consequently distributed among the marketplace, wallet interfaces, smart-contract design and the person approving the signature.

What remained uncertain on February 19

OpenSea’s estimate of 32 users was an investigative count, not a final victim total. Reports attaching dollar values to the removed NFTs also depended on assumptions about collection floor prices, prior sales or subsequent attacker sales. NFTs are non-fungible, so such estimates were not equivalent to cash withdrawn or a contemporaneous executable market quote. This reconstruction therefore does not assign an event-day dollar loss.

It was also not established on February 19 whether victims had received fraudulent emails, visited one common website or encountered several lures. Describing the event as a confirmed OpenSea platform hack would have exceeded the evidence available that night.

Later clarification

On February 21, OpenSea revised the affected-user count from 32 to 17, explaining that the original figure included anyone who interacted with the attacker rather than only users who lost assets. That later correction strengthens the phishing interpretation but should not be projected backward as information available when the investigation opened on February 19.

Primary sourceEtherscan record for the contract associated with the campaign

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.