A Customer.io employee accessed OpenSea’s email database and shared it with “an unauthorized external party,” the NFT marketplace said.
OpenSea warned of potential phishing attacks in an announcement of the data breach.
OpenSea Email Database Leaked
Someone has leaked OpenSea’s email database.
The top NFT marketplace published a blog post early Thursday warning its community that an employee of its email vendor, Customer.io, had shared a list of email addresses of its users and newsletter subscribers with “an unauthorized external party.”
The post explained that a Customer.io employee had misused their position to gain access to the list and share it with an unnamed third party. OpenSea warned users to be wary of potential phishing attacks following the breach, saying “there may be a heightened likelihood for email phishing attempts.” It also warned users against sharing cryptocurrency wallet passwords and signing transactions posted via email links. Though OpenSea did not confirm whether the breach included cryptocurrency wallet data, it said anyone who has shared an email address with the company “should assume [they] were impacted.”
OpenSea has also said that it is looking into the incident with Customer.io. “We are working with Customer.io in their ongoing investigation, and we have reported this incident to law enforcement,” the post read.
Today’s breach is the latest in a string of troubling incidents affecting OpenSea users. While the leading NFT marketplace has so far only confirmed a data leak rather than a full-scale attack, it’s suffered from phishing attacks and other issues in the past. Last month, an attacker hacked the OpenSea Discord server and directed users to mint fake “YouTube Genesis Mint Passes.” In February, a bad actor stole about $3 million worth of NFTs from OpenSea users by tricking them into signing a malicious transaction sent via an email link. The marketplace has also faced scrutiny over listing bug issues in the past.
OpenSea is the world’s largest NFT marketplace. According to data from Token Terminal, it handled over $483 million in transaction volume in June 2022.
Disclosure: At the time of writing, the author of this piece owned ETH, some NFTs, and several other cryptocurrencies.
The information on or accessed through this website is obtained from independent sources we believe to be accurate and reliable, but Decentral Media, Inc. makes no representation or warranty as to the timeliness, completeness, or accuracy of any information on or accessed through this website. Decentral Media, Inc. is not an investment advisor. We do not give personalized investment advice or other financial advice. The information on this website is subject to change without notice. Some or all of the information on this website may become outdated, or it may be or become incomplete or inaccurate. We may, but are not obligated to, update any outdated, incomplete, or inaccurate information.
You should never make an investment decision on an ICO, IEO, or other investment based on the information on this website, and you should never interpret or otherwise rely on any of the information on this website as investment advice. We strongly recommend that you consult a licensed investment advisor or other qualified financial professional if you are seeking investment advice on an ICO, IEO, or other investment. We do not accept compensation in any form for analyzing or reporting on any ICO, IEO, cryptocurrency, currency, tokenized sales, securities, or commodities.
See full terms and conditions.
Latest OpenSea Attack Sees Hacker Infiltrate Discord
The OpenSea Discord server was hacked early Friday morning. A series of posts from a compromised OpenSea Discord server bot directed users to mint a “YouTube Genesis Mint Pass” from…
OpenSea NFT Hack Exposes Web3 Self-Custody Risks
The hacker stole hundreds of high-value NFTs from sought-after collections like Bored Ape Yacht Club, Azuki, and NFT Worlds. OpenSea Users Targeted in NFT Hack A hacker stole millions of…
NFT Collector Sues OpenSea for $1M Over Listing Bug
An NFT collector who inadvertently sold a Bored Ape Yacht Club NFT for $26 due to an OpenSea listing issue has filed a lawsuit asking for $1 million in damages….