Other
"This NFT on OpenSea Will Steal Your IP Address"
Primary Source ↗Incident Details
MetaMask acknowledged a week ago that they’d failed to address an IP leakage “issue has been widely known for a long time”. The issue is present in many NFT marketplaces and wallets, including both MetaMask and OpenSea, and presents potential privacy concerns for anonymous collectors or anyone concerned about potentially having their IP (and as a result, often geolocation information) exposed to any NFT creator. Some researchers and engineers have begun creating NFT projects that gather IPs and display them back to the viewers, as a way to highlight the vulnerability.This is as good a time as any to remind you to use a VPN! Mullvad is a particularly good pick (#NotAnAd).
Technical Details
- Initial Attack Vector
- Software bug / unintentional loss
- Vendor / Product
- IP harvesting NFTs created
Timeline
- 2022-01-27 Breach occurred
- 2022-01-27 Publicly disclosed