Supply chain
⛓ Supply Chain
OpenSea Third-Party Breach (June 2022)
Primary Source ↗Incident Details
OpenSea users’ email addresses leaked in data breach. If you’ve shared your email address with the NFT marketplace, you should assume to be impacted. The company is working with Customer.io to investigate the matter. “Please stay vigilant about your email practices, and be alert for any attempt to impersonate OpenSea via email,” wrote Hardman. Unlike a previous phishing attack on OpenSea in February that resulted in hundreds of NFTs being stolen, there appears to be no further reported damage beyond the leaked email addresses. Still, the number of people likely impacted by the breach is significant. Hackread noted that 1.8 million users made purchases through the Ethereum network on OpenSea, according to data from Dune Analytics. Third-party company: Customer.io.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Customer.io
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2022-06-01 Breach occurred
- 2022-06-30 Publicly disclosed