{"id":4647,"date":"2022-02-25T22:38:47","date_gmt":"2022-02-26T00:38:47","guid":{"rendered":"https:\/\/teknomers.com\/fr\/les-pirates-ont-vole-17-million-de-dollars-de-nft-aux-utilisateurs-dopensea-marketplace\/"},"modified":"2022-02-25T22:39:00","modified_gmt":"2022-02-26T00:39:00","slug":"les-pirates-ont-vole-17-million-de-dollars-de-nft-aux-utilisateurs-dopensea-marketplace","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/les-pirates-ont-vole-17-million-de-dollars-de-nft-aux-utilisateurs-dopensea-marketplace\/","title":{"rendered":"Les pirates ont vol\u00e9 1,7 million de dollars de NFT aux utilisateurs d&#8217;OpenSea Marketplace"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Des acteurs malveillants ont profit\u00e9 d&#8217;un processus de mise \u00e0 niveau de contrat intelligent sur le march\u00e9 OpenSea NFT pour effectuer une <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/PeckShieldAlert\/status\/1495281343927767040\" target=\"_blank\">une attaque par phishing<\/a> contre 17 de ses utilisateurs qui ont entra\u00een\u00e9 le vol d&#8217;actifs virtuels d&#8217;une valeur d&#8217;environ 1,7 million de dollars.<\/p>\n<p><a rel=\"nofollow noopener\" href=\"https:\/\/en.wikipedia.org\/wiki\/Non-fungible_token\" target=\"_blank\">NFT<\/a>abr\u00e9viation de jetons non fongibles, sont des jetons num\u00e9riques qui agissent comme des certificats d&#8217;authenticit\u00e9 et, dans certains cas, repr\u00e9sentent la propri\u00e9t\u00e9 d&#8217;actifs allant des illustrations co\u00fbteuses aux objets de collection et aux biens physiques.<\/p>\n<p>L&#8217;escroquerie d&#8217;ing\u00e9nierie sociale opportuniste <a rel=\"nofollow noopener\" href=\"https:\/\/etherscan.io\/address\/0x3e0defb880cd8e163bad68abe66437f99a7a8a74#internaltx\" target=\"_blank\">escroqu\u00e9 les utilisateurs<\/a> en utilisant le m\u00eame e-mail d&#8217;OpenSea informant les utilisateurs de la mise \u00e0 niveau, l&#8217;e-mail imitant redirigeant les victimes vers une page Web similaire, les invitant \u00e0 signer une transaction apparemment l\u00e9gitime, pour voler tous les NFT en une seule fois.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/dset2\" target=\"_blank\" title=\"Automatic GitHub Backups\"><img loading=\"lazy\" decoding=\"async\" alt=\"Sauvegardes GitHub automatiques\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/Alertes-CISA-sur-les-failles-activement-exploitees-dans-la-plate-forme.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>&#8220;En signant la transaction, une requ\u00eate atomicMatch_ serait envoy\u00e9e au contrat de l&#8217;attaquant&#8221;, ont d\u00e9clar\u00e9 les chercheurs de Check Point. <a rel=\"nofollow noopener\" href=\"https:\/\/blog.checkpoint.com\/2022\/02\/20\/new-opensea-attack-led-to-theft-of-millions-of-dollars-in-nfts\/\" target=\"_blank\">expliqu\u00e9<\/a>.  &#8220;A partir de l\u00e0, l&#8217;atomicMatch_ serait transmis au contrat OpenSea&#8221;, conduisant au transfert des NFT de la victime \u00e0 l&#8217;attaquant.<\/p>\n<div class=\"separator\" style=\"clear: both\"><img decoding=\"async\" alt=\"Place de march\u00e9 OpenSea\" border=\"0\" data-original-height=\"580\" data-original-width=\"728\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/1645835926_207_Les-pirates-ont-vole-17-million-de-dollars-de-NFT.jpeg\" title=\"Place de march\u00e9 OpenSea\" \/><\/div>\n<p>d&#8217;OpenSea&#8221;<a rel=\"nofollow noopener\" href=\"https:\/\/support.opensea.io\/hc\/en-us\/articles\/4433163594643-Smart-Contract-Upgrade-How-to-Migrate-Your-Item-Listings\" target=\"_blank\">Wyvern<\/a>&#8221; La migration des contrats intelligents, qui a commenc\u00e9 le 18 f\u00e9vrier sur une p\u00e9riode de sept jours jusqu&#8217;au 25 f\u00e9vrier \u00e0 14h00 HE, fait partie des efforts de la soci\u00e9t\u00e9 bas\u00e9e \u00e0 New York pour traiter les anciennes listes inactives existantes sur la blockchain Ethereum.<\/p>\n<div class=\"separator\" style=\"clear: both\"><img decoding=\"async\" alt=\"Place de march\u00e9 OpenSea\" border=\"0\" data-original-height=\"598\" data-original-width=\"728\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/1645835927_983_Les-pirates-ont-vole-17-million-de-dollars-de-NFT.jpeg\" title=\"Place de march\u00e9 OpenSea\" \/><\/div>\n<p>le <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/dfinzer\/status\/1495273300876042240\" target=\"_blank\">entreprise<\/a> <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/NadavAHollander\/status\/1495509511179755530\" target=\"_blank\">mentionn\u00e9<\/a> c&#8217;est toujours <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/opensea\/status\/1495625768713469954\" target=\"_blank\">enqu\u00eatant<\/a> la source exacte de l&#8217;attaque, notant que les ordres malveillants avaient \u00e9t\u00e9 sign\u00e9s par les victimes avant qu&#8217;OpenSea n&#8217;effectue sa migration.  &#8220;L&#8217;attaque ne semble plus \u00eatre active, mais nous continuons \u00e0 surveiller. Nous n&#8217;avons pas vu d&#8217;activit\u00e9 du portefeuille de l&#8217;attaquant depuis plus de 36 heures&#8221;, OpenSea <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/opensea\/status\/1495996847546335237\" target=\"_blank\">mentionn\u00e9<\/a> dans une mise \u00e0 jour.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/cs-jan-webinar-inside\" target=\"_blank\" title=\"Prevent Data Breaches\"><img loading=\"lazy\" decoding=\"async\" alt=\"Emp\u00eacher les violations de donn\u00e9es\" class=\"lazyload\" src=\"https:\/\/thehackernews.com\/new-images\/img\/a\/AVvXsEioBAdGzzhUsdR9KeCFA035yyXX3qvL_N0C5wEpRzoxSGOuJkegXomXUYhgD1rM50Z-58n_8vMFpuazXCcsUfDNuXBR1DGjxmTPWg17VRE4xLar0TNTWg0Gz793cp4E2mfZYRKWDPYVo_q2ll3EI7GUIQJQTeAl29y1BlB-bBtFSfU-v2DDJZijFG3Uzw=s728-e100\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>&#8220;Signer une transaction revient \u00e0 donner \u00e0 quelqu&#8217;un la permission d&#8217;acc\u00e9der \u00e0 tous vos NFT et crypto-monnaies&#8221;, a d\u00e9clar\u00e9 Check Point.  &#8220;C&#8217;est pourquoi la signature est tr\u00e8s dangereuse. Portez une attention particuli\u00e8re \u00e0 l&#8217;endroit et au moment o\u00f9 vous signez une transaction.&#8221;<\/p>\n<p>Le d\u00e9veloppement intervient \u00e9galement alors que les cybercriminels exploitent la popularit\u00e9 croissante des NFT pour inciter les victimes \u00e0 t\u00e9l\u00e9charger le <a rel=\"nofollow noopener\" href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/nft-lure-used-to-distribute-bitrat\" target=\"_blank\">Cheval de Troie d&#8217;acc\u00e8s \u00e0 distance BitRAT<\/a> des logiciels malveillants capables de voler les informations d&#8217;identification du navigateur, d&#8217;exploiter la crypto-monnaie et de collecter des informations sensibles.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/02\/hackers-steal-17-million-worth-of-nfts.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Des acteurs malveillants ont profit\u00e9 d&#8217;un processus de mise \u00e0 niveau de contrat intelligent sur le march\u00e9 OpenSea NFT pour effectuer une une attaque par phishing contre 17 de ses utilisateurs qui ont entra\u00een\u00e9 le vol d&#8217;actifs virtuels d&#8217;une valeur d&#8217;environ 1,7 million de dollars. NFTabr\u00e9viation de jetons non fongibles, sont des jetons num\u00e9riques qui [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":4648,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[507,4168,4158,4165,4161,2414,7530,4157,4159,4171,4170,65,4167,7531,358,4160,4043,4163,4162,249,4394,4172,4169,7529,4166,1661,4164],"class_list":["post-4647","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-aux","tag-comment-pirater","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-dollars","tag-dopensea","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-les","tag-logiciel-malveillant-de-ransomware","tag-marketplace","tag-million","tag-mises-a-jour-de-la-cybersecurite","tag-nft","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-ont","tag-pirates","tag-securite-informatique","tag-securite-internet","tag-utilisateurs","tag-violation-de-donnees","tag-vole","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/4647","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=4647"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/4647\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/4648"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=4647"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=4647"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=4647"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}