Slow Fog: Beware of Phishing Risks from Bulk Listing Signature "Zero Purchase" in the Blur NFT Market
ChainCatcher message, recently, SlowMist's ecological security partner Scam Sniffer demonstrated a "zero-cost purchase" phishing attack test targeting bulk order signatures on the Blur NFT market. With a "Root signature" like the one shown in the image, it is possible to lure away all NFTs authorized by the target user on the Blur platform at a very low cost (specifically "zero-cost purchase"). The "Root signature" format on the Blur platform is similar to "blind signing," making it difficult for users to recognize the impact of such signatures. The SlowMist security team has verified the feasibility and harm of this attack.This is a reminder for all users of the Blur platform to be vigilant. If you encounter a "Root signature" from a non-Blur official domain (blur.io), be sure to reject it to avoid potential asset loss.