Cryptocurrency [loss] $800

"Ferrari subdomain hijacked to push fake Ferrari NFT collection"

2022-05-06 [vendor] Ferrari domain hijacked [chain] ethereum
Primary Source ↗
Financial Loss $800 (800 USD)
Blockchain(s) Ethereum

Incident Details

Someone was able to gain control of a ferrari.com subdomain to create a scam NFT mint. Most scam NFT projects rely on eager NFT collectors not noticing a URL that isn’t quite right — for example, something like ferrari-nft.com. This one was able to gain some additional legitimacy by using an actual ferrari.com subdomain. Additionally, Ferrari had recently announced an upcoming NFT project, making the scam project seem more plausible.Sadly for the scammer, the scam was discovered and shut down when they had only managed to scam one person. The unsuspecting collector sent 0.3 ETH ($800), which the scammer transferred to Tornado Cash.

Total loss estimated at $800.

Technical Details

Initial Attack Vector
Smart contract exploit / hack
Vendor / Product
Ferrari domain hijacked

Timeline

  1. 2022-05-06 Breach occurred
  2. 2022-05-06 Publicly disclosed