OpenSea said on February 21, 2022 that 17 people, rather than the 32 initially identified, had lost non-fungible tokens in a phishing incident involving orders executed through its marketplace infrastructure. The company explained that its first count included every address that had interacted with the attacker, not only addresses from which assets were taken.
The revision was consequential because it replaced a rapidly circulating preliminary figure with the marketplace’s narrower victim count. OpenSea also said the malicious contract appeared inactive: its public update reported no activity for more than 15 hours. That observation indicated the immediate transfer campaign might have stopped, but it did not establish that the attacker had abandoned the assets, that every victim had been identified or that further phishing attempts were impossible.
What the records showed
Reports of missing NFTs emerged on February 19 and February 20, 2022, while OpenSea was moving existing Ethereum listings to an upgraded contract. OpenSea had opened the migration on February 18 and set February 25 as the deadline for users who wanted their older listings to remain active. The legitimate migration created a plausible pretext for fraudulent messages asking users to approve transactions.
Check Point Research’s contemporaneous analysis described a phishing site that imitated the migration process. According to the researchers, a victim who followed the malicious link was asked to sign an order. The attacker could pass that signed order through a helper contract and invoke the Wyvern Exchange contract used by OpenSea. Because the required parameters carried the victim’s valid cryptographic signature, the contract could execute transfers even though the signature had allegedly been obtained through deception.
Ethereum records for the helper contract identified by Check Point show a cluster of transactions on February 19 and February 20. The latest transaction visible in that contract’s principal history was timestamped February 20 at 11:42:15 UTC. That record is consistent with OpenSea’s inactivity statement, although it does not independently prove that every address or contract controlled by the attacker had stopped operating.
Phishing claim remained under investigation
OpenSea’s event-day position was that the incident did not originate from its website and that the evidence pointed to phishing rather than exploitation of a vulnerability in the newly deployed marketplace contract. Its chief technology officer said the malicious orders contained valid user signatures and were signed before the migration began. Those were attributable company findings on February 21, not a completed independent forensic determination.
The distinction mattered. A protocol exploit would have suggested that an attacker could bypass the marketplace’s intended authorization rules. The phishing explanation instead indicated that the rules processed signatures as designed, while users were misled about what they were authorizing. The episode therefore exposed a broader weakness in wallet-based markets: a valid signature can be technically sufficient for a transfer even when the signer does not understand the transaction’s effect.
Loss estimates required caution
OpenSea co-founder Devin Finzer rejected online claims that the incident represented a $200 million theft. On February 20, he said the attacker’s wallet contained about $1.7 million in ether from selling some stolen NFTs. That figure was a wallet-proceeds observation, not a verified valuation of every NFT removed from affected users.
NFT loss estimates were especially uncertain because tokens could have recent sale prices, asking prices, model-derived estimates or no liquid market at all. The defensible February 21 record was therefore limited: OpenSea counted 17 victims, investigators linked the transfers to allegedly deceptive signatures, and the precise origin and total economic loss remained unresolved.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

