OpenSea said on February 20, 2022 that it believed a phishing campaign—not an exploit originating on its website—had caused users to lose NFTs after signing a malicious payload. Co-founder and chief executive Devin Finzer said the company had identified 32 affected users at that stage of the investigation and was contacting them to determine where the deceptive signatures had been solicited.
The distinction mattered because early reports had described the episode as a possible failure of OpenSea-related smart contracts. OpenSea was the dominant general-purpose NFT marketplace, and it was simultaneously asking Ethereum users to migrate active listings to a newer version of its trading contract. A security incident linked to that transition could have implicated the marketplace’s core infrastructure; a phishing operation would instead point to attackers exploiting user authorization and the urgency surrounding a legitimate migration.
What OpenSea had established
OpenSea’s February 20 statements ruled out several vectors based on its investigation and conversations with affected users. The company said activity on the opensea.io domain, legitimate OpenSea emails, its website banner, and ordinary minting, buying, selling or listing actions were not believed to be responsible. Finzer also said signing the new Wyvern 2.3 contract and using OpenSea’s listing-migration tool were not identified as attack vectors.
Those were contemporaneous company findings, not a complete independent post-mortem. OpenSea had not established where every victim encountered the malicious request, and the available statements did not identify the attacker. The company’s warning therefore remained appropriately narrow: users had apparently signed something dangerous outside the normal OpenSea workflow, but the distribution channel was still under investigation.
Finzer also challenged claims that the attacker had taken $200 million. His stated figure was approximately $1.7 million of ether held by the attacker from selling some stolen NFTs. That number described observed sale proceeds in the wallet at the time; it was not a verified appraisal of every transferred NFT, a calculation of victims’ net losses, or a measure of assets later returned.
How the signatures were used
Check Point Research published a technical assessment on February 20 after examining public reports and Ethereum activity. Its researchers believed the attacker imitated OpenSea’s migration messaging and directed victims to a site that requested a signature. According to that assessment, the signed data enabled an `atomicMatch_` request to pass through an attacker-controlled contract and then the Wyvern exchange contract used for OpenSea trading.
Wyvern could execute the exchange because the relevant order carried the victim’s valid cryptographic authorization. The blockchain could verify the signature and transfer conditions, but it could not determine whether the signer had been deceived by a website or message. That separation between technically valid authorization and informed consent was the episode’s central infrastructure lesson.
Ethereum records for the attacker-linked contract identified by Check Point show transactions dated February 19 and February 20, 2022 UTC. Those records corroborate the timing and interaction pattern, but address labels and transaction histories alone do not prove who controlled the contracts, how each signature was obtained, or the dollar value of every NFT.
Why the incident mattered
OpenSea had announced a $300 million funding round at a $13.3 billion post-money valuation on January 4, 2022, after reporting that its transaction volume increased more than 600-fold during 2021. The February incident therefore tested security expectations around one of the NFT sector’s most prominent institutions at a moment of rapid growth.
It also demonstrated that self-custody did not eliminate intermediary risk. The NFTs remained associated with users’ Ethereum wallets, but marketplace-compatible signatures could still authorize irreversible transfers. Security depended not only on contract code and custody arrangements, but also on whether wallet interfaces made the scope and destination of a requested signature intelligible.
Later context
On February 21, 2022, OpenSea revised the affected-user count from 32 to 17 after excluding accounts that appeared to have interacted with the attacker without losing items. That later revision should not be projected into what OpenSea reported on February 20.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

