Other

"This NFT on OpenSea Will Steal Your IP Address"

2022-01-27 [vendor] IP harvesting NFTs created
Primary Source ↗

Incident Details

MetaMask acknowledged a week ago that they’d failed to address an IP leakage “issue has been widely known for a long time”. The issue is present in many NFT marketplaces and wallets, including both MetaMask and OpenSea, and presents potential privacy concerns for anonymous collectors or anyone concerned about potentially having their IP (and as a result, often geolocation information) exposed to any NFT creator. Some researchers and engineers have begun creating NFT projects that gather IPs and display them back to the viewers, as a way to highlight the vulnerability.This is as good a time as any to remind you to use a VPN! Mullvad is a particularly good pick (#NotAnAd).

Technical Details

Initial Attack Vector
Software bug / unintentional loss
Vendor / Product
IP harvesting NFTs created

Timeline

  1. 2022-01-27 Breach occurred
  2. 2022-01-27 Publicly disclosed