Cointime

Download App
iOS & Android

OpenSea Addresses Scammers With New Collection Settings, but They Create New Issues for NFT Teams

So, I ran into a new and exciting issue on OpenSea yesterday as I was doing some setup for a new ETH smart contract — claiming and setting up the collection on OpenSea.

As most people who’ve been in the space for a while already know, scammers are everywhere in web3. And since there’s so much $$$ in the NFT space, scammers have complicated matters for marketplaces and for NFT teams alike.

Here’s an example of the problem I’ll address here: You’re doing an NFT drop in the next 6 months. It’s going to be called “Nuclear Cat Squad.” (I just made that up. Hopefully there isn’t an actual “Nuclear Cat Squad” already.)

Anyway, so you start doing your various hyping on Twitter and elsewhere, pasting sample NFTs, building up your audience, etc.

At first no one cares because it’s tough to get noticed. But after months of work, you’ve got yourself 10,000 Twitter followers and word is spreading. All is going well.

And then… someone on your Discord says, “Hey, what’s this?” And they link to a collection on OpenSea. Some scammer has collected every single preview image you’ve posted, created an OpenSea account / collection, and has of course taken the name “Nuclear Cat Squad” as well as the URL “nuclearcatsquad” (which is what OpenSea uses for the URL of your collection).

The above scenario has happened about 8 million times to people. It’s actually something that, very early on, we all expected to happen. And so we came up with this process:

Our Previous Solution

To avoid this, we would always advise our clients to grab a temp wallet, go to OpenSea, and setup a whole bunch of collections. We would have them setup “Nuclear Cat Squad” as well as “Nuclear Cats” and “Nuclear Cat Squad NFT” and various other similar names (and also similar URLs). To some extent, this seemed to have deterred scammers, although you can never get ALL of the names you want, and scammers will find a way.

Anyway, when it came time to launch, we would deploy the contract, mint an NFT, and then head over to OpenSea to setup the actual collection. We would have the client login to OpenSea at the same time, and we would have them change “Nuclear Cat Squad” (and the “nuclearcatsquad” URL) to something else (like “Nuclear Cat Squad Old” and “nuclearcatsquadold”). This would free up the names for us to use, using their deployer wallet. And thus, we’d get the actual, desired name and url for the collection.

We’ve actually got a handful of clients with forthcoming collections who’ve done the above already.

OpenSea’s New Code

Yesterday, though, I noticed that the above approach no longer works. When I had the client go in and change his “Nuclear Cat Squad” and “nuclearcatsquad” to something else, it didn’t let me take the name (even if it DID indicate that the name was free). Instead, it alerted me that the name was “too similar” to something else that existed already.

It suggested I reach out to support if there is something wrong. (So, I did that. Will update with their resoponse.)

What’s Wrong Here…

So, I suspect this is one of those good/bad moves that coders can make sometimes. You implement a fix, but the fix creates new problems!

It’s a good thing for existing collections, of course. If someone tries to start a new “Bored Ape Yacht Club,” it’s going to know (rightly so) that this is probably a scam.

But OpenSea’s solutions creates a big problem for unlaunched collections: If NFT teams can no longer create temp / placeholder collections to reserve the official names, then it’s almost 100% certain that scammers will be grabbing/using those names/urls before any collection launches. That’s what they’ve always done, and that’s what they’ll certainly continue to do.

Thus, launching a collection will ALWAYS be a problem from here on out on OpenSea. Anytime you launch, you’re going to clash with whatever scam set has grabbed the name and URL you’d wanted. And so you’re going to have to contact support and hopefully work it out. But that’s going to take time, which is not always in high supply during an NFT launch.

What Does OpenSea Recommend?

I’m awaiting a response to a support ticket on that, in which I’ve asked this question. Will update with their recommendation, if they respond.

NFT
Comments

All Comments

Recommended for you

  • SlowMist: Beware of watering hole attacks launched by malicious attackers using WordPress plugin vulnerabilities

    SlowMist Security has issued a warning that attackers have recently been exploiting vulnerabilities in WordPress plugins to inject malicious JS code into normal websites and launch watering hole attacks. These attacks involve popping up malicious windows when users visit the site, deceiving them into executing malicious code or performing Web3 wallet signatures, thereby stealing their assets. It is recommended that sites using WordPress plugins check for vulnerabilities, update plugins in a timely manner, and avoid being attacked. When visiting any website, users should carefully identify the downloaded programs and Web3 signature content to avoid downloading malicious programs or having their assets stolen due to malicious signatures.

  • Unverified Ember Sword NFT auction contract vulnerability has caused nearly $200,000 in losses

    Certik has discovered a vulnerability in the unverified Ember Sword NFT auction contract, which has earned 60 WETH (approximately $195,000) from 159 victims who approved the contract. Certik reminds users to revoke their approval of the relevant contract on Polygon.

  • zkSync ecological lending platform xBank Finance suspected of RUG

    xBank Finance, a zkSync ecosystem lending platform, was suspected of being a RUG, and the protocol's TVL was close to zero. The project's official Twitter account has been frozen.

  • Scammers use fake USDT balances to defraud cryptocurrency users

    SlowMist has partnered with Imtoken to uncover a new cryptocurrency scam that uses offline transactions and USDT. Scammers manipulate the Ethereum RPC to falsify the USDT balance in the victim's wallet. The scammer lures the victim to change their Ethereum RPC URL to a URL controlled by them, making it appear that the victim has deposited USDT funds, but in reality, the victim is left empty-handed when attempting to trade. In addition, the scam also deceives users through small transfers to gain trust, then manipulates account balances and contract information, posing serious risks to unsuspecting users and is related to a wider range of pig slaughter scam activities.

  • Cointime April 27th News Express

    1. ETH falls below $3,100

  • HKEX: Accepts BOS HashKey, Huaxia, Harvest Bitcoin and Ethereum ETFs as eligible securities for multiple counters in the central clearing system

    On April 27th, the Hong Kong Stock Exchange issued three notices, announcing the inclusion of Bo Shi HashKey Bitcoin ETF shares and Bo Shi HashKey Ethereum ETF shares, Huaxia Bitcoin ETF shares and Huaxia Ethereum ETF shares, and Jia Shi Bitcoin Spot ETF shares and Jia Shi Ethereum Spot ETF shares as Central Clearing System multi-counterparty eligible securities. It is reported that:

  • Russia’s Central Bank and Rosfinmonitoring unveil pilot of fiat-to-crypto tracking system

    According to reports, since 2023, Russia has been trying to track cryptocurrency transactions and their sources. The Russian Central Bank and the Federal Financial Monitoring Service (Rosfinmonitoring) revealed that there is currently a system that allows private banks to track the connection between fiat-based transactions and cryptocurrency business.

  • PolkaWorld: Coretime trading on Kusama has started

    On April 27th, PolkaWorld announced that Coretime trading on Kusama has begun, marking the end of the era of parallel chains. With the approval and implementation of Kusama proposal 373, the proposal will upgrade the Kusama relay chain runtime to v1.2.0 and bring Coretime functionality. Shortly thereafter, the Kusama community approved Kusmaa proposal 375 last Friday, allowing Coretime chain to begin selling Coretime. Currently, Kusama is in the Renew Period and is selling batches of Coretime.

  • Over $155 million worth of MEME will be unlocked on May 3, accounting for 31.96% of the circulating supply

    According to Token Unlocks data, 5.31 billion MEME tokens, worth over $155 million, will be unlocked on May 3, 2024, accounting for 31.96% of the circulating supply. These tokens will be unlocked and distributed to airdrops, advisors, and investors.

  • The total open interest of BTC options is $17.83 billion, and the open interest of ETH options is $8.07 billion.

    Coinglass data shows that the nominal value of unclosed BTC option positions on the entire network is 17.83 billion US dollars, which is the lowest point since February 26; the nominal value of unclosed ETH option positions is 8.07 billion US dollars, which is the lowest point since February 25.