CCT - Crypto Currency Tracker logo CCT - Crypto Currency Tracker logo
crypto.news 2025-01-13 09:12:32

Leaked OpenSea user emails now public, SlowMist warns of phishing risks

Over 7 million OpenSea users are at risk after email addresses compromised in a 2022 data breach were recently made fully public. According to blockchain security firm SlowMist’s chief information security officer, 23pds, the leaked data significantly increases the risk of phishing and other attacks. In a Jan. 13 X post , the security researcher alerted crypto community members that the compromised data had been disseminated multiple times before it was publicized. 23pds added that the leaked data includes email addresses belonging to prominent figures in the cryptocurrency industry, such as former Binance CEO Changpeng “CZ” Zhao, as well as well-known companies, key opinion leaders, and other influential individuals, warning that it poses additional risks to the privacy and asset security of the crypto industry in the future. The email addresses in question were compromised in a June 2022 incident involving an employee of Customer.io, OpenSea’s email delivery vendor, who misused their access to download and share email addresses provided by OpenSea users and newsletter subscribers with an unauthorized external party. At the time, the non-fungible token marketplace advised users to be on the lookout for phishing and impersonation attempts, warning against downloading attachments or signing wallet transactions from email links, adding that all official communication would come only from its ‘opensea.io’ domain. You might also like: OpenSea to launch new platform next month, CEO says As one of the largest NFT marketplaces, OpenSea users have been targeted by phishing scammers on several occasions. Just months after the data leak, in December 2022, a blockchain security platform alerted users that attackers were using phishing websites to exploit OpenSea’s gasless transaction feature. Victims were tricked into signing unintelligible signature requests, which unknowingly authorized private sales or immediate transfers of valuable NFTs to the account of the attackers. In November 2023, OpenSea developers were targeted by phishing campaigns, including fake developer account risk alerts, leading some experts to believe developer contact information may have been breached. Similarly, in January 2024, scammers sent emails to OpenSea users promising an exclusive mint event for a limited edition NFT collaboration between Nike and RTFKT. The email claimed recipients were among 400 selected participants and included a link to “Mint RTFKT Now,” which reportedly directed victims to a malicious website designed to steal wallet information or funds. Phishing scams remain a major threat for cryptocurrency enthusiasts due to the many forms they come in, making them difficult to trace and even harder to prevent effectively. Experts advise users to stay vigilant by verifying email sources, avoiding clicking on unknown links, enabling two-factor authentication, and never sharing private wallet keys or sensitive information online. Read more: Pudgy Penguin NFT price exceeds Bitcoin’s price on OpenSea

阅读免责声明 : 此处提供的所有内容我们的网站,超链接网站,相关应用程序,论坛,博客,社交媒体帐户和其他平台(“网站”)仅供您提供一般信息,从第三方采购。 我们不对与我们的内容有任何形式的保证,包括但不限于准确性和更新性。 我们提供的内容中没有任何内容构成财务建议,法律建议或任何其他形式的建议,以满足您对任何目的的特定依赖。 任何使用或依赖我们的内容完全由您自行承担风险和自由裁量权。 在依赖它们之前,您应该进行自己的研究,审查,分析和验证我们的内容。 交易是一项高风险的活动,可能导致重大损失,因此请在做出任何决定之前咨询您的财务顾问。 我们网站上的任何内容均不构成招揽或要约