Cybercriminals have stolen over $100 million in NFTs: Report – Decrypt



According to a new report from blockchain analysis firm Elliptic, more than $100 million in NFTs have been stolen in the past year. The report, “NFTs and Financial Crimes,” released Wednesday, covers nefarious crypto activity between July 2021 and July 2022.

According to Elliptic, in addition to stolen NFTs, more than $8 million in illicit money has been laundered using NFTs since 2017. Non-fungible tokens, better known as NFTs, are cryptographically unique tokens linked to digital and physical content that provide proof of ownership.

Elliptic says cybercriminals made an average of $300,000 per scam. Its report stated that $24 million in NFTs were stolen through scams in May 2022 alone, with July 2022 being the highest month on record for the number of NFTs stolen at 4,600.

“The actual numbers are likely higher, as thefts are not always publicly reported,” Elliptic says. The firm says that these unreported thefts are usually low-priced NFTs.



According to the report, 23% of all NFTs stolen in 2022 came from compromised social media platforms such as Discord and phishing messages sent to members.

Image: Elliptical

Other attack methods tracked by Elliptic include phishing emails, malicious websites, and—as in the case of the Solana hack, earlier this month—an exploit in a mobile wallet.

According to the firm, the most valuable NFT stolen ever was Cryptopunk #4324, which netted thieves $490,000 in November 2021. In December 2021 losses of 16 “blue chip” NFTs worth $2.1 million.

Elliptic says that NFTs lost in the scams include Bored Apps, Mutant Apps, Azuki, Otherside and CloneX.

“In total, these five collections constitute more than two-thirds of the stolen NFT value since July 2021,” Elliptic says.

Unsurprisingly, bored Ape Yacht Club NFT is one of the most sought after by cybercriminals. According to Elliptic, the stolen Bored Apps accounted for $43.6 million in stolen NFTs.

In June, Family Guy star Seth Green paid $300,000 to recover his stolen Bored app NFT after falling victim to a phishing attack.

Image: Elliptical

The report also cited the hacking of Axi Infinity’s Ronin Ethereum sidechain bridge in March 2022 by the North Korean Lazarus Group. It also noted that the recently approved Tornando cash mixing service, saying that over $160,000 in digital assets from approved entities has been used to purchase NFTs.

“Although crime represents a small proportion of overall NFT trading, it has an adverse effect on the reputation of the industry and undermines the quality of experience for legitimate users,” Elliptic says.

Adding to this impact on reputation, Elliptic says that cybercriminals are becoming more sophisticated and bypassing verification protocols such as the now-defunct “Verified by Civic Pass” program from decentralized identity verification company Civic. In January, despite being “verified”, scammers made around $1.3 million at the time, with 9136 SOLs.

Fake NFTs are also a major concern. In January, the report said, OpenC reported that more than 80% of NFTs used its tool to “plagiarize works, counterfeit collections and spam”.

Stay on top of crypto news, get daily updates delivered to your inbox.

Source



Related News