Major Leak of OpenSea Customer Emails

  • According to the NFT marketplace, its customers’ emails were leaked to an outside party by an employee of Customer.io.
  • The company has reported the incident to law enforcement officials, and reminded its customers to be weary of phishing attacks.
opensea hack

Shutterstock

Non-fungible tokens (NFTs) marketplace OpenSea issued a warning after the list of its customers’ emails was leaked to an outside party, the company said in a blog post on Thursday.

According to the announcement, the phishing emails warning was issued once OpenSea learned that an employee of Customer.io — a platform for managing email campaigns and newsletters — leaked the list of its customers’ emails to a third party. The company noted that this breach has affected all of the users who had given their email to the marketplace, whether for the platform or its newsletter.

The world’s largest NFT marketplace said it had already contacted law enforcement officials about the breach, and that an investigation is in progress. OpenSea also reminded its users that the malicious actors are likely to contact them via emails from similar domains, such as OpenSea.org or OpenSea.xyz.

Newsletter management platforms appear to be a weak spot for crypto firms as of late, with data leaks continuing to happen. Back in March, Hubspot — a platform with similar services as Customer.io — was hacked, exposing usernames, phone numbers, and emails of customers from BlockFi, Swan Bitcoin, NYDIG, and Circle.

This is not the first time the NFT marketplace has suffered a data breach this year, with OpenSea falling victim to a hack of its Discord server back in May, with numerous wallets getting exploited in the process. Back in January, an exploit on the platform allowed an attacker to sell a number of NFTs without permission — with the marketplace reimbursing $1.8 million in losses — while in February, 17 wallets had their NFTs stolen following a phishing attack.

Discussion
Related Coverage
Vitalik Says X Account Hacked Via SIM-Swap
  • Ethereum co-founder Vitalik Buterin has regained his T-Mobile account, which on Saturday was compromised by hackers and used to take over his X account.
  • On 9 September, hackers used a SIM-swap attack to take over Buterin’s X account, and siphon close to $700,000 in crypto by promoting a fake NFT giveaway.
September 12, 2023, 1:33 PM
Vitalik Buterin Proposes Creating an Ether Mixer

Ethereum co-founder and Vitalik Buterin speaks during TechCrunch Disrupt. 18 September, 2017, San Francisco, California.Steve Jennings/Getty Images for TechCrunch

Kroll Data Breach Compromises FTX, BlockFi Customer Information
  • A cyber security incident at bankruptcy service provider Kroll has resulted in the exposure of “non-sensitive” customer data for claimants involved in the FTX and BlockFi cases.
  • Both companies confirmed that account passwords, systems, and funds remained safe, but warned customers to be on the lookout for phishing scams.
Terra Freezes Website, Warns Against Phishing Scams
  • Blockchain network Terra said its website was compromised by hackers over the weekend, and warned users against ongoing phishing scams.
  • The platform later froze its website to prevent the hackers from exploiting it, and reminded users to avoid websites with the terra.money domain for now.