Cryptocurrency [loss] $1M+

Tweet from Becerra announcing the theft

2021-10-31 [vendor] Calvin Becerra NFT theft [chain] ethereum
Primary Source ↗
Financial Loss $1.0M (1,000,000 USD)
Blockchain(s) Ethereum

Incident Details

NFT collector Calvin Becerra fell for some social engineering on Discord: “Guys posing as buyers in Discord were helping me troubleshoot a problem we thought was happening… They walked me through language settings in my MetaMask and had me choose an option and took everything.” The scammers obtained three of his “Bored Ape Yacht Club” NFTs (one pictured), which collectively valued around $1 million. Becerra successfully lobbied OpenSea, Rarible, and NFT Trader to block sales of the stolen NFTs, though some viewed the NFT exchanges’ intervention as a demonstration that these exchanges can indeed interfere with access to the blockchain.

Total loss estimated at $1,000,000.

Technical Details

Initial Attack Vector
Social engineering attack
Vendor / Product
Calvin Becerra NFT theft

Timeline

  1. 2021-10-31 Breach occurred
  2. 2021-10-31 Publicly disclosed