Cointime

Download App
iOS & Android

Issues Around NFTs: Risks, Challenges, and Regulatory Landscape

Validated Media

The NFTs experienced a meteoric rise this year. reportedly, the booming NFTs market generated over $23 billion in trading volume this year, compared to just $ 94.9 million in 2020. However, greater commercial viability and an increase in the trading volume have also resulted in an increased risk of fraudulent activities such as AML/CFT risks, phishing attacks, and copyright violations. Naturally, the risks associated with NFTs have also captured the attention of regulators all around the globe. On February 4, 2022, the U.S. Department of Treasury published a study, warning the investors that NFTs may, potentially, become a tool for money laundering in the high-value art market. Shortly after that, on February 14, 2022, BBC reported that Her Majesty’s Revenue and Customs (HMRC), the chief tax authority in the United Kingdom, has seized three NFTs as part of a probe into a suspected value-added tax (VAT) fraud case involving 250 alleged fake companies.

Risks in NFTs

Phishing Attacks

Phishing is a type of cyber attack where a malicious actor poses as a reputable entity or business to deceive people and collect their sensitive information. Within the context of the  NFTs market, attackers often focus on obtaining the private key of the digital wallet. 

To purchase an NFT, the users have to set up a crypto-wallet. Metamask is a popular cryptocurrency wallet on the Ethereum blockchain that provides support for NFTs. MetaMask customers were targeted in a phishing scam that involved phony ads asking for their private wallet keys and 12-word security phrases. On February 19, 2022, the leading NFT marketplace OpenSea, lost $1.7 million worth of NFTs in a phishing attack. The attackers exploited flexibility in the Wyvern protocol, an NFT exchange protocol used by OpenSea. Reportedly, the attacker posing as Opensea sent out an email to the users urging them to authorize a migration of their NFT listings to the new Wyvern contract. After clicking on the link, it appears the users signed transactions that gave the hacker permission to drain their wallets. 

In order to protect themselves from phishing attacks, buyers should avoid keeping Bitcoin, Litecoin, and NFTs in a single wallet. Instead, the buyers should store NFTs in hardware wallets and enable two-factor authentication. Hardware wallets are offline wallets that store the users’ private keys in a secure hardware device.  Since private keys are stored offline, it is difficult for attackers to gain access to them.

NFTs buyers and creators should double-check NFT marketplace offers and email links, since, attackers often create identical copies of popular collectibles or send out fake notifications impersonating popular NFT marketplaces. Further, attackers may also replicate popular NFT marketplaces, like OpenSea, in order to create fake NFT stores. Since these sites look identical to the original platforms, buyers can be tricked into spending large amounts of money on a fake artwork that is, in reality, worth nothing.

Counterfeit or plagiarized NFTs

The NFTs marketplace is ripe with plagiarism-related fraud cases. On February 6, 2022, Cent, one of the first NFT marketplaces to allow users to sell tweets as NFTs, suspended all of its activities due to plagiarism issues, In a tweet, digital artist Lois van Baarle said she had discovered “132 instances” of her artwork being minted as NFTs on the marketplace OpenSea, all without her permission. She further added that “NFTs are supposedly about authenticity, but these platforms do less than the bare minimum when it comes to making sure that the images are being uploaded by their original creators.”

Most NFT marketplaces do not have a mechanism for determining the authenticity of the NFTs being sold on their platforms. Some NFT marketplaces such as Rarible put a “verified” checkmark on the page of a creator whose works it has deemed authentic; however, the vast majority of artists on these platforms are unverified, this allows scammers to sell copies of original NFTs tokens.

Before buying an NFT from any marketplace, buyers must do their research to make sure that the NFT that they are buying is from a verified account. For instance, in the OpeanSea platform, they must look for a blue checkmark next to the creator’s profile picture.

Pump-and-dump schemes

pump-and-dump scam is when a group of traders, such as founders or collaborators, spread misleading or false information to inflate the price of an asset before selling off their shares at a higher price. Pump-and-dump schemes in the NFTs markets usually involve influencers who are compensated for encouraging people to buy a particular NFT, in order to, increase its value. Once the value of the NFT rises and artificial demand has been created the scammers and influencers cash out and the buyers are left with worthless assets.

Smart contract risks in NFTs

NFTs are deployed using smart contracts. Further, using smart contracts developers place hard caps on the supply of NFTs and enforce persistent properties that cannot be modified after the NFTs are issued. Logic errors in a smart contract take place when a developer writes code that makes smart contracts susceptible to attacks, such as software bugs. Post-launch, CryptoPunks, a popular NFT token collection platform discovered a bug in their smart contract. After 10,000 Punks, a bug was discovered where sales could occur but no actual payment was received. Additionally, if the rights governing the ownership are not clearly defined in the smart contract, the buyer may lose his assets.

Money laundering

Like more traditional digital assets, NFTs face heightened money laundering risks due to the ease of conducting transactions and the pseudonymous nature of blockchains. NFT marketplaces are vulnerable to money laundering, both from bad actors buying and selling NFTs to criminals creating their own NFTs and self-dealing to launder the funds. Self laundering is a process in which users spend money on an NFT they already own to conceal transaction traces on the blockchain. Under this process, the criminals first purchase an NFT using illicit funds. They then continue to transact with themselves to create records of sales on the blockchain. Post this, the NFTs will be sold to an individual who will compensate the criminal with clean funds not tied to the prior crime.

Self-laundering is particularly concerning, as NFTs can be set up to provide a transaction fee to the NFT’s creator each time it is sold. This could allow bad actors to continue to profit from their illicit, self-dealing funds long after they are originally laundered, by selling NFTs to unsuspecting third parties.

NFTs Regulatory Landscape

The FATFs’ Updated Guidance for a Risk-Based Approach to Virtual Assets (VAs) and Virtual Asset Service Providers (VASPs), stated that though NFTs or crypto-collectibles generally fall outside the virtual asset definition they may be considered such if used for payment or investment purposes in practice.

The U.S. Department of Treasury, recently, published a study on the facilitation of AML/CFT through art trade.  According to the study, platforms that support the sale and purchase of NFTs, as well as virtual mediums like metaverses can be regulated as money services businesses (MSBs) under the Financial Crimes Enforcement Network (FinCEN) regulations. These service providers, therefore, will be subjected to existing KYC/AML regulations. To this end, the study explains that “to understand the application of AML/CFT obligations, it is important to consider the nature of the business dealing in NFTs and their function in practice as well as the facts and circumstances of the platform or other person doing business.”

The U.S. Department of Treasury particularly emphasized that peer-to-peer transactions of NFTs in the absence of any intermediaries, with or without any record on a public ledger may also give rise to AML/CFT concerns. The report observed that “the ability to transfer some NFTs via the internet without concern for geographic distance and across borders nearly instantaneously makes digital art susceptible to exploitation by those seeking to launder illicit proceeds of crime because the movement of value can be accomplished without incurring potential financial, regulatory, or investigative costs of physical shipment.”

On February 15, 2022, the Monetary Authority of Singapore (MAS) in a written response to questions posed by the parliament on the subject of NFTs, MAS  announced that it will not be regulating activities related to NFTs in the near future. However, the regulator also stated that will keep an eye on the NFT's space. “Should an NFT be structured to represent rights to a portfolio of listed shares, it will like other collective investment schemes be subject to prospectus requirements, licensing and business conduct requirements,” concluded Tharman Shanmugartnam, senior minister and minister in charge of the MAS

The HMRC seized three NFTs worth $1.89 million in a suspected case of a tax probe. The HMRC is the first law enforcement body in the UK to make NFT seizures. The seizure forms part of a suspected VAT tax fraud case involving 250 fake shell companies. Three suspects have been arrested on the suspicion of attempting to defraud the HMRC. Basically, the suspects tried to claim back more VAT than what was owed to them. Further, the HMRC stated the suspects used various sophisticated methods to hide their identities such as false and stolen identities, false addresses, pre-paid unregistered mobile phones, Virtual Private Networks (VPNs), and false invoices.

NFT
Comments

All Comments

Recommended for you

  • Tevaera Closes $5 Million Funding Round to Create One-Stop Gaming Ecosystem Powered by zkSync's ZK Stack

    Tevaera, a gaming platform powered by zkSync's ZK Stack, has closed a $5 million funding round led by Laser Digital and Nomura Group. The funding will support Tevaera's mission to create a one-stop gaming ecosystem. The project has attracted prominent investors, including Hashkey Capital, Fenbushi Capital, and Crypto.com Capital. Tevaera has also launched a redesigned website and is preparing to introduce two new games and the first decentralized L3 gaming chain on zkSync.

  • The Hong Kong Securities Regulatory Commission’s official website has listed the Bitcoin and Ethereum spot ETFs and stock codes of China Asset Management, Bosera and Harvest.

    Hong Kong Securities and Futures Commission website has listed the Bitcoin and Ethereum spot ETFs of three fund companies, Huaxia, Boshi, and Jiashi, with approval dates all on April 23, 2024. The related funds are not derivative product funds, specifically including:1. Huaxia Bitcoin ETF (BUU163) with share codes of 03042, 09042, and 83042;2. Huaxia Ethereum ETF (BUU164) with share codes of 03046, 09046, and 83046;3. Boshi HashKey Bitcoin ETF (BUU104) with share codes of 03008 and 09008;4. Boshi HashKey Ethereum ETF (BUU105) with share codes of 03009 and 09009;5. Jiashi Bitcoin Spot ETF (BUT244) with share codes of 03439 and 09439;6. Jiashi Ethereum Spot ETF (BUU885) with share codes of 03179 and 09179.

  • Correction: Nigeria’s central bank says “freezing Bybit, KuCoin, OKX, Binance user accounts” is unofficial

    The official X account of the Central Bank of Nigeria (CBN) stated that the announcement "the Central Bank of Nigeria will freeze Bybit, KuCoin, OKX, and Binance user accounts" is not an official release. Previously, according to Cointelegraph, the Central Bank of Nigeria (CBN) issued an instruction requiring all banks and financial institutions to identify individuals or entities trading with cryptocurrency exchanges and ensure that such accounts receive no debit (PND) instructions within six months.

  • Alliance of 314: The X314 contract is suspected to have a hidden additional issuance switch, developers should pay attention to verification

    Alliance of 314 issued a statement claiming that the contract of a certain 314 project has not been open-sourced on the blockchain. As for whether other platforms have open-sourced their contracts, there is a misconception that open-sourcing on other platforms is self-submitted and does not necessarily mean that the contract is deployed on the chain, so there may be unknown hidden issuance. Additionally, the said 314 project announced that it will soon launch a trading platform, and the first requirement for logging into a centralized exchange is to open-source the contract. Open-sourcing is the first thing that any project should do to ensure investor confidence. Referring to the open-sourcing of the 0.1, 0.5, and 0.9 versions before, it can be concluded that there is hidden code in the X314 contract, and therefore it cannot be open-sourced out of fear. The biggest risk warning: after decompiling and querying ethervm, it is highly suspected that a certain 314 has a hidden issuance switch to increase mining pool output and arbitrage. The field is as follows: 0x40c10f19mint(address,uint256). The risk alert level for this switch is the highest level, and generally, ordinary developers do not set this switch.

  • UNVEILING THE CELESTIAL MASTERY: TREVOR JONES’ CRYPTOANGELS PROJECT

    Renowned digital artist Trevor Jones, a visionary in the fusion of traditional art with blockchain technology, is set to transcend boundaries with his latest project, CryptoAngels. This ambitious initiative is not merely an art drop; it’s a comprehensive ecosystem encompassing physical and digital realms, games, and a vibrant community engagement, promising to be a cornerstone event in the NFT landscape of 2024.

  • Binance Founder Faces Potential Three-Year Prison Sentence and $50 Million Fine for Money Laundering and Sanctions Violations

    Binance founder Changpeng Zhao has been recommended a three-year prison sentence by federal prosecutors for violating federal money laundering laws and sanctions. The Department of Justice argued that this sentence would hold him accountable for his intentional criminal conduct and send a message to the world. Zhao made a "business decision" to break the law to attract users, build his company, and line his pockets, according to prosecutors. Along with the prison sentence, DOJ lawyers also requested that Zhao pay the $50 million fine he agreed to as part of a plea deal. Zhao, who is a citizen of the UAE and Canada, has been released on a $175 million bond but must remain in the U.S. until his sentencing on April 30.

  • Market News: South Africa authorizes 75 companies as cryptocurrency service providers

    According to Jinshi news, South Africa has authorized 75 companies as cryptocurrency service providers.

  • Indonesian President: $8.6 billion laundered through cryptocurrency in 2021

    According to Golden Finance News, Indonesian President Joko Widodo stated that he has noticed signs of money laundering through cryptocurrency in 2021, amounting to $8.6 billion (IDR 139 trillion). In addition to cryptocurrencies and NFTs, the president emphasized the need to monitor other potential money laundering tools, including virtual assets, market activities, e-currencies, and AI-driven transactions. Mahendra Siregar, Chairman of the Financial Services Authority (OJK) Committee, responded to the President's directive, stating that when cryptocurrency regulation is transferred to the OJK next year, his agency will supervise these issues.

  • BTC breaks through $67,000

    Tthe market shows that BTC has broken through $67,000 and is now trading at $67,025.99, with a daily increase of 1.12%. The market is volatile, please be prepared for risk control.

  • Bitcoin spot ETF had a total net inflow of $31.6354 million yesterday, and the ETF net asset ratio reached 4.27%

    According to SoSoValue data, the total net inflow of Bitcoin spot ETF was $31.6354 million on April 23 (US Eastern Time).Grayscale ETF GBTC had a net outflow of $66.8838 million on April 23, and the historical net outflow of GBTC is $16.833 billion.The Bitcoin spot ETF with the highest net inflow on April 23 was BlackRock ETF IBIT, with a net inflow of $37.9233 million in a single day, and the historical total net inflow of IBIT has reached $15.479 billion.The second highest was the ARKB ETF from Ark Invest and 21Shares, with a net inflow of $33.282 million in a single day, and the historical total net inflow of ARKB has reached $2.267 billion.As of now, the total net asset value of Bitcoin spot ETF is $55.82 billion, and the ETF net asset ratio (the proportion of market value to the total market value of Bitcoin) is 4.27%, with a historical cumulative net inflow of $12.416 billion.