"The Sandbox" Instagram ATO.
Queries valuable NFTs via: /boredapeyachtclub.shoes:3001/methods/appraise?address=
Whenever the transferring of NFTs fail, the malicious actor redirects the user to a fake Metamask pop-up to phish the recovery phrase: /sandbox-claim.xyz/metamask/MetaMaskConfirm.html
Exfil to the same fake bored ape domain: /boredapeyachtclub.shoes:3000/data