Skip to content
October 1, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • Technique
  • How Not to Compromise Yourself When Dealing With NFTs
  • Technique

How Not to Compromise Yourself When Dealing With NFTs

Do Son March 22, 2022 6 minutes read
NFT

Rokas Tenys/Shutterstock.com

Rokas Tenys/Shutterstock.com

The biggest hype in the IT, emerging technology, and digital investment industries is NFTs a.k.a the Non-Fungible Token. This is deemed to be the next big thing following the cryptocurrency revolution that took hold of the world during the last decade. It is the second most well-known offspring of the blockchain revolution, following cryptocurrency. NFTs are still a very abstract concept, more so an unorthodox one. Most people find it difficult to understand the purpose of NFTs, and they are still quite gimmicky. To be more specific, the utility of NFTs is hardly understood by most. It is still a very new concept that early adopters have taken on, and supposedly some people are already profiting from NFTs. For others, NFTs may seem ridiculous or childish, but if they follow the same path of cryptocurrencies such as Bitcoin or Ethereum, it would be a good idea to get invested in them now and to do that safely. After all, what we have seen so far from the blockchain is that blockchain technologies are bound to be revolutionary. Whatever your outlook on digital assets such as NFTs is, you must be safe with your digital assets for a variety of reasons. Nobody should enter the world of digital assets without solid security practices, just like you wouldn’t drive a car without a seatbelt. After all, this is the finances we’re talking about.

What are NFTs?

After the appearance of the mysterious “Satoshi Nakamoto” online in 2009, a pseudonym for the father of the blockchain which is still a mystery in real life, the concept of the “blockchain” was unraveled for the world to see. The famous technical white paper describing blockchain technology was what led to cryptocurrency, and now NFTs.

NFTs, however, is not quite the same as a cryptocurrency such as Bitcoin. Yes, NFTs are digital assets however that is where the similarities stop. Every Bitcoin is, for instance, identical however NFTs are unique. On the other hand, they can leverage and be bought via the cryptocurrency known as Ethereum (ETH) and are often based on ERC-721 tokens. NFTs can come in the form of digital art, digital media, and more and can be traded, like old-school trading cards. They can also come in the form of a domain name, a tweet, or just about any digital item with a value attached to it. The reason NFTs are “non-fungible” is because each of the tokens is unique, not equal like cryptocurrency is, which makes cryptocurrency “fungible.”

NFTs are quickly becoming popular in the artwork business and you can buy NFT domains, with over $150 million in sales registered the future applications of NFTs could span from the Metaverse to virtual real estate contracts and digital avatars. For these reasons, NFTs must be kept safe just like you would keep your cryptocurrency in a safe place. Like any digital good that has financial value, NFTs can be traded across digital currency exchanges and converted. Furthermore, just like any digital asset NFTs can be compromised, stolen, or lost too.

How to be Safe When Dealing With NFTs

Like any digital asset, things become very sensitive once the monetary value is attached to them. For this reason, several people are extremely paranoid about their cryptocurrency “wallets” and the security-conscious will keep their BTC, ETH, or otherwise on a “cold wallet” that is offline. Very few people will keep their currency in a web extension or what is known as a “hot wallet.” This is because exchanges can be hacked (and they often are), hackers can intercept unsecured connections, and human error can cause digital assets to be lost, either virtually or physically. There is a saying in the NFT community known as FOMO or Fear Of Missing Out. This is also a significant driver of human error, as you can tell.

The issue is that once lost it is very difficult to return and, because it is still an experimental space, authorities are not involved at this point. This is particularly the case for “blue chip” NFTs which are deemed very valuable and are a target for hackers and scammers. Just recently, one of the biggest NFT exchanges (OpenSea) was hacked, for instance.

So, what can you do to ensure maximum security and privacy with your NFT collection? Here are some quick tips;

  • Never click on links that cannot be verified
  • Triple check domain links, because these can be spoofed
  • When you are “minting” (creating) an NFT, make sure the link is verified by verifying the official collection’s social media
  • Do not interact with NFTs sent to your wallet that are unverified
  • Triple check Twitter handles, there are many fake accounts present
  • Stay away from suspicious emails such as offers from NFT exchanges
  • Never send anyone your “seed phrase”
  • Never send anyone your “recovery phrase”
  • Do not share your screen with anyone
  • Use strong passwords
  • Activate multi-factor authentication on your accounts

These quick tips are there to teach you basic NFT OPSEC (what is known as operations security), meaning using your common sense. Once you are armed with these security measures and risks, you should avoid most of the security problems associated with digital assets, discounting those that are out of your hands (like a crypto exchange hack).

Adding to this, you will need a network security cybersecurity tool known as a VPN, or Virtual Private Network, at your disposal. You must not browse the internet without this, especially when buying or selling anything. This will block anyone from “sniffing” your connection and compromising it. A VPN will anonymize you, so you must use a premium VPN such as NordVPN. Most importantly, avoid those phishing scam emails that are looking to dupe you into giving over your credentials, and stay away from scammers on platforms such as Discord and Twitter. In public, try to avoid public WiFi hotspots and keep your eye out for people scanning your laptop or smartphone with their eyes, or worse, trying to take pictures of what you are doing.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-58155CVSS 9.2
    Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects...
    📅 Updated: Oct 1, 2026
  • CVE-2026-58154CVSS 9.2
    Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This...
    📅 Updated: Oct 1, 2026
  • CVE-2026-13043CVSS 9.3
    A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows...
    📅 Updated: Oct 1, 2026
  • CVE-2026-96658CVSS 9.9
    A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE)...
    📅 Updated: Oct 1, 2026
  • CVE-2026-96659CVSS 9.1
    A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause...
    📅 Updated: Oct 1, 2026
  • CVE-2026-13014CVSS 9.2
    A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code...
    📅 Updated: Oct 1, 2026
  • CVE-2026-94620CVSS 9.4
    Classroom 50 is a free and open-source tool for managing and grading programming assignments via GitHub. Prior to...
    📅 Updated: Oct 1, 2026
  • CVE-2026-95284CVSS 9.6
    Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to...
    📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.