Dan Romero
@dwr.eth
Would be curious what @aman @scharf think happened with the Kevin Rose hack? https://twitter.com/0xquit/status/1618335012176400384?s=46&t=EDpYmItVCL0dWiilP6A4TA
12 replies
0 recast
0 reaction
Aman Dhesi
@aman
It was a seaport bulk listing attack - Kevin signed a gasless signature that sold all his NFTs for 0ETH to the attacker. The attacker then submitted the signature to the Seaport contract and that executed the "sale". We're in the process of recreating the original signature and writing a post-mortem
3 replies
0 recast
0 reaction
Aman Dhesi
@aman
This is the transaction that executed the signature https://etherscan.io/tx/0x4ae899024f8bfcb3448364dc603db2e6ed4eab7b3a8649176230d7e33e644d44
0 reply
0 recast
0 reaction
Sterling
@sterling
yeah similar question - how is this different than signing a txn to prove ownership for premint, tokenproof, collabland, etc. ? or is it not and that's the terrifying bit?
1 reply
0 recast
0 reaction
Dan Romero
@dwr.eth
Naive question: is this a gasless signature as well? Feels like thinking that since there's no transaction confirmation it's OK to sign? https://i.imgur.com/tAgs4hY.png
2 replies
0 recast
0 reaction