OpenSea, the largest non-fungible token (NFT) marketplace, revealed a data breach and warned users of phishing attacks that could target them.
The online NFT marketplace states it has more than 600,000 users and a transaction volume that surpassed $20 billion.
The company’s Head of Security, Cory Hardman, said that an employee of Customer.io, the platform’s email delivery vendor, downloaded email addresses belonging to OpenSea users and newsletter subscribers.
Since the emails stolen in the incident were also shared with an unauthorized external party, Hardman urged potentially affected users to be alert for phishing attempts impersonating OpenSea.
Hardman stated that they are working with Customer.io in their ongoing investigation, and they have reported this incident to law enforcement.
As the compromised data included email addresses, there may be a chance for email phishing attempts.
The users were also warned to look for emails sent from domains that malicious actors could use to spoof OpenSea’s official email domain opensea.io.
He recommends that the users can defend against phishing attempts by being suspicious of any emails trying to impersonate OpenSea, not to download and open email attachments, and to check the URLs of pages linked in OpenSea emails.
Users must not share or confirm their passwords or secret wallet phrases and never sign wallet transactions if prompted directly via email.
Image Credits : World Trademark Review














Comments