By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Private Banks RankingPrivate Banks Ranking
Notification Show More
Latest News
Anya Kartashova
USI Travel Insurance Review: Is It Worth It?
Personal Finance
Bitcoin Crashes as SEC Sues Coinbase, Binance. Where Prices Could Stop Falling.
Bitcoin Crashes as SEC Sues Coinbase, Binance. Where Prices Could Stop Falling.
Finance
ECB’s Lagarde sees no peak in core inflation despite ‘moderation’
Business
Factbox: Highlights from SEC complaint against crypto exchange Binance
Banking
Custodia Bank denied Fed membership, master account
Banks could face 20% capital buffer increase: report
Banking
Aa
  • Finance
  • Business
  • Banking
  • Investing
  • ETFs
  • Mutual Fund
  • Personal Finance
  • 2022 RANKING
Reading: OpenSea fixes a major vulnerability that could have leaked your identity
Share
Private Banks RankingPrivate Banks Ranking
Aa
  • Finance
  • Business
  • Banking
  • Investing
  • ETFs
  • Mutual Fund
  • Personal Finance
  • 2022 RANKING
Search
  • Finance
  • Business
  • Banking
  • Investing
  • ETFs
  • Mutual Fund
  • Personal Finance
  • 2022 RANKING
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Private Banks Ranking > Blog > Cryptocurrency > OpenSea fixes a major vulnerability that could have leaked your identity
Cryptocurrency

OpenSea fixes a major vulnerability that could have leaked your identity

By Private Banks Ranking 3 months ago
Share
4 Min Read
OpenSea fixes a major vulnerability that could have leaked your identity
SHARE
  • The loophole on OpenSea when successfully exploited could have allowed the attacker to obtain the identities of users.
  • OpenSea quickly fixed the issue after the vulnerability came to the fore.

Cyber security company Imperva detected a major vulnerability on popular NFT marketplace OpenSea, which when successfully exploited, could allow the attacker to obtain the identities of users on the platform.

Contents
Tainted PastTrading activity declines

According to Imperva, the misconfiguration of the iFrame-resizer library used by OpenSea was the main reason behind the vulnerability.

Providing more details about the exploitation mechanism for the issue, Imperva stated that the attacker would send a link through email or SMS.

If the victim clicks on the link, vital information such as the target’s IP address, user agent, device details, and software versions would be retrieved.

Cross-site search vulnerability would then be exploited to get the target’s NFT names and the attacker would then associate the leaked NFT/public wallet address with the email or phone number where the link was initially sent to.

However, Imperva’s report mentioned that OpenSea had fixed the issue after it was reported and the marketplace was no longer at risk of such attacks

Tainted Past

OpenSea has faced serious concerns over the platform’s security in the past. In February 2022, it was at the center of one of the biggest hacks in the NFT ecosystem.

During the exploit, $1.7 million worth of NFTs were stolen from users’ wallets. The breach was acknowledged by OpenSea CEO Devin Finzer.

Another update: over the last few hours we’ve talked to dozens of people, teams, and projects across the NFT space. https://t.co/fB5r3cMA1r

— Devin Finzer (dfinzer.eth) (@dfinzer) February 20, 2022

In less than three months, the marketplace was hit again when its discord channel was compromised. The hackers posted a fake YouTube collaboration news that included a link to a phishing site.

See also  Analyst Benjamin Cowen Says Bitcoin Could Be on Cusp of Major Trend Shift As Potential Repeat of 2019 Appears

The impact of the hacks made OpenSea take some concrete steps to safeguard its users. Last month, it introduced a grace period of three hours during which sellers will be prevented from accepting offers after a supposed sale.

Trading activity declines

Meanwhile, OpenSea saw a significant dip in the trading activity on the platform since mid-February. The weekly NFT trading plunged 40% until press time, as per data from Token Terminal.

As a consequence of this, the royalties paid to creators also declined. The weekly supply-side fees plunged 40% at the time of writing, which could dissuade interested creators from listing their work on the marketplace.

Source: Token Terminal

OpenSea had been hit hard because of the Blur [BLUR] storm that swept the NFT marketplace ecosystem. As per data from Dune Analytics, OpenSea’s share in the total trading volume across all marketplaces was reduced to 26%.

However, it still managed to hold on to a significant chunk of the user base and the total number of sales, with a dominance of 62.8% and 51% respectively.

Source: Dune Analytics



Source link

You Might Also Like

Major central banks were expected to pause rate hikes soon. Now it’s not so clear cut

All Major Property Types Post Annual Declines

IRS flagged more than 1 million tax returns for identity fraud in 2023

Natural gas prices are bottoming, major investor suggests

First Republic’s failure shows need for major deposit insurance reform

TAGGED: fixes, identity, leaked, Major, OpenSea, vulnerability
Share this Article
Facebook Twitter Email Print
Share
Previous Article From Santa Clara to Shoreditch, SVB Fallout Spreads Around World From Santa Clara to Shoreditch, SVB Fallout Spreads Around World
Next Article Bitcoin Ordinals could help BTC miners in the long-run- Here's how Bitcoin Ordinals could help BTC miners in the long-run- Here’s how
Leave a comment

Leave a Reply Cancel reply

You must be logged in to post a comment.

Private Banks RankingPrivate Banks Ranking
Follow US

© 2022 Private Banks Ranking- 85 Great Portland Street,W1W 7LT, London. All Rights Reserved.

  • Blog
  • Contact
  • Privacy Policy
  • Terms & Conditions
Join Us!

Subscribe to our newsletter and never miss our latest news, podcasts etc..

I have read and agree to the terms & conditions
Zero spam, Unsubscribe at any time.

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?