OpenSea NFT users report massive email phishing campaign

MARKET_WATCH

NFT

Users of the major nonfungible token (NFT) marketplace OpenSea have said they are being targeted with a new email phishing attack and have received emails containing malicious links from attackers posing as the marketplace.

 

According to social media reports, OpenSea users and developers have been targeted by various email phishing campaigns, including a fake developer account risk alert and a fake NFT offer.

 

One OpenSea developer took to X (formerly Twitter) on Nov. 13 to report receiving a phishing attempt at an email strictly dedicated to their OpenSea Application Programming Interface (API) key. “In other words, dev contacts have been exfiltrated from OpenSea and are the real target in this campaign,” the post read.

 

The social media report came in response to OpenSea’s insistence that the platform has not been hacked and urging users not to click on links they don’t trust.

 

Another OpenSea user took to Reddit to express confusion about the ongoing phishing campaign on Nov. 14.

“Haven’t used OpenSea for years and all of a sudden, I keep getting emails talking about my NFT listings getting offers,” the poster wrote, adding that all the vulnerable links were trying to direct the reader to install a malicious app.

 

“Right now I’m getting 3-4 scam/phishing emails a day which is crazy since I got zero just a few weeks ago,” the Redditor wrote, adding:

 

“So my question is did something new happen to OpenSea. The email address of mine they are hitting is one I created specifically for OpenSea so not concerned but I know OpenSea had hacks previously. Are they just now hitting up my email or is there a new one?”

 

The news comes a few weeks after one of OpenSea’s third-party vendors experienced a security incident that exposed information related to user API keys. OpenSea reported the breach in a notification email to affected users in late September 2023, stating that user emails and developer API keys may have been leaked due to the attack.

 

OpenSea users have received phishing emails previously. In February 2022, OpenSea officially confirmed that its platform faced a phishing attack from outside the OpenSea website and urged users to stay away from clicking on any links in the emails. The firm was also investigating rumors of an exploit associated with OpenSea-related smart contracts.

 

OpenSea did not immediately respond to Cointelegraph’s request for comment.

 

This latest phishing campaign is happening just after OpenSea laid off 50% of its staff, with the stated intention of launching OpenSea 2.0 with a smaller team.

 

This attack is yet another reminder for the cryptocurrency community to stay vigilant when receiving emails from service providers. To avoid a phishing hack, users should be cautious of the email sender’s authenticity and the associated links. Users should also remember that crypto firms never ask their users for personal data like wallet addresses or private keys.

 

Source : Cointelegraph By Helen Partz / Nov 15, 2023

rayn.finance logo

Automata FRANCE SAS

240 rue Evariste Galois,

06410 Biot,

Sophia Antipolis

Automata Pay

65-66 Warwick House 4th

Floor, Queen Street, London

England, EC4R 1EB

Automata Pay Europe Ltd

3rd Floor Ormond Building,

31-36 Ormond Quay Upper,

Dublin 7, D07 Ee37

Automata ICO Ltd

Succursale Italienne

Via Archimede, 161,

00197 Roma

Italy

L’achat d’actifs numériques est soumis à un risque de marché élevé et à la volatilité des prix. Les changements de valeur peuvent être significatifs et se produire rapidement et sans avertissement. Les performances passées ne sont pas un indicateur fiable des performances futures. La valeur d’un investissement et les rendements peuvent varier à la hausse comme à la baisse, et il se peut que vous ne récupériez pas le montant que vous avez investi. MISE EN GARDE CONTRE LES RISQUES

Automata ICO Limited dispose d'une succursale en Italie dont le siège social est situé Via Archimede, 161, Roma, Italie. La société est enregistrée auprès de l’Organisme des agents et médiateurs ("AOM") sous le numéro 96550860587 en tant que Prestataire de Services en Actifs Numériques (“PSAN”).

Automata France SAS est une société française enregistrée et immatriculée sous le numéro SIREN 902 498 617. La société est enregistrée auprès de l’Autorité des Marchés Financiers (“AMF”) sous le numéro E2023-087 en tant que Prestataire de Services en Actifs Numériques (“PSAN”).

Automata France SAS est partenaire de Modulr Finance B.V., une société enregistrée aux Pays-Bas sous le numéro d'entreprise 81852401, qui est autorisée et réglementée par la Banque centrale néerlandaise (DNB) en tant qu'Établissement de Monnaie Électronique (Numéro de référence de la société : R182870) pour l'émission de monnaie électronique et les services de paiement. Votre compte et les services de paiement associés sont fournis par Modulr Finance B.V. Vos fonds seront détenus sur un ou plusieurs comptes ségrégués et protégés conformément à la Loi sur la Surveillance Financière. Comment nous assurons la sécurité de votre argent.