Cryptocurrency

Tweet by Pranksy

2022-01-16 [vendor] NotASecretNFT project [chain] ethereum
Primary Source ↗
Blockchain(s) Ethereum

Incident Details

Enthusiasts rushed to buy NFTs from a project called NotASecretNFT after seeing NFT mega-whale Pranksy buy in, even though the OpenSea description was simply, “1000 secrets, endless lies… Farming $LIES starts 24 hours from mint.” After funds were drained from the project, Pranksy tweeted, “Ok you may have seen me buy some NotASecretNFT’s from opensea - it looks like this was a rug pull / scam, please do not buy anymore based on my purchases and revert any permissions you may have given”. A note in the project’s smart contract read, “Hello world, Nothing was intended to be obscured from you, you simply did not follow the clues.” In a tweet thread, one buyer explained how he didn’t research the project himself, but bought in after seeing an alert that Pranksy had bought NFTs. He ended the thread by writing, “Never buy into hypes and always #DYOR [do your own research]. Lesson learned once more!”

Technical Details

Initial Attack Vector
Exit scam / rug pull
Vendor / Product
NotASecretNFT project

Timeline

  1. 2022-01-16 Breach occurred
  2. 2022-01-16 Publicly disclosed