Forex Trading Review
  • LyoPay
  • VXL Dollar
  • Hyperfund
  • Darren Yaw
What's Hot

Škoda Investice platform Review 2023 – Doubtful service attracts dizzying earnings, it’s a scam

March 23, 2023

REVOLUT Review 2023: Experience, Fees, Card, Buy Stocks & Cryptocurrencies, Discussions, Scam

March 23, 2023

FTX seeks to claw back $460M from Bankman-Fried-backed VC firm

March 23, 2023
Facebook Twitter Instagram
  • LyoPay
  • VXL Dollar
  • Hyperfund
  • Darren Yaw
Facebook Twitter Instagram
Forex Trading Review
  • Crypto

    Digital currency firms eye operations in Hong Kong: Financial secretary

    March 23, 2023

    Philippines places 54th in UNCTAD ranking for innovative tech adoption

    March 23, 2023

    Swiss Banking Association proposes deposit tokens focusing on interoperability

    March 23, 2023

    Tron founder Justin Sun, 8 celebrities hit with market manipulation and illegal securities charges

    March 23, 2023

    ‘The aim of Bitcoin is to be a micropayment system’: Dr. Craig Wright

    March 23, 2023
  • Forex

    VXL Dollar – Bijan Burnard – Scam Warning 2023

    January 22, 2023

    Golden Brokers Ltd: Why You Must Avoid This Shady Broker

    January 20, 2023

    Alpho Review: A Suspicious Broker You Should Avoid

    December 29, 2022

    Gulf Brokers DMCC: Shady and Suspicious

    December 19, 2022
  • Alerts

    ClearPath Lending – Veteran Scam – 2023

    January 30, 2023

    Golden Brokers Ltd: Why You Must Avoid This Shady Broker

    January 20, 2023

    Lear Capital – Shady Firm Scamming Investors & Facing Multiple Lawsuits

    January 20, 2023

    Is Birch Gold Group a Scam? Let’s find out.

    January 18, 2023

    Stanislav Kondrashov – Financier of Wagner ’s Army

    December 27, 2022
  • News

    FTX seeks to claw back $460M from Bankman-Fried-backed VC firm

    March 23, 2023

    ‘How did this happen’ — Powell says Fed stumped over the collapse of SVB

    March 23, 2023

    CFTC’s tech committee gathered in DC to talk DeFi — Here’s what was discussed

    March 23, 2023

    Coinbase CEO on its Wells notice: SEC is like soccer referees in a game of pickleball

    March 23, 2023

    Aussie crypto exchange hints interest in Hong Kong base

    March 23, 2023
  • Scams

    DaVinci Biosciences and DV Biologics – Human Organ Traffickers

    February 19, 2023

    Vito Glazers – Perjury and Fraud – Investigation 2023

    February 18, 2023

    VXL Dollar – Bijan Burnard – Scam Warning 2023

    January 22, 2023

    GulfBrokers – GulfBrokers.com – Review 2023

    January 20, 2023

    Ravi Melwani – Sexual Harassment Charges, Rape Accusations – 2023 Investigation

    January 13, 2023
  • Reviews
    1. Darren Yaw
    2. Hyperfund
    3. LyoPay
    4. VXL Dollar
    5. View All

    Škoda Investice platform Review 2023 – Doubtful service attracts dizzying earnings, it’s a scam

    March 23, 2023

    REVOLUT Review 2023: Experience, Fees, Card, Buy Stocks & Cryptocurrencies, Discussions, Scam

    March 23, 2023

    Tastyworks Review 2023: Experience with the broker, fees, instructions, demo, discussion, scam

    March 23, 2023

    VIRAROSO Review 2023: ViraRoso Crypto Cryptocurrency Broker Experience, Fees, Discussions, Scam

    March 23, 2023
Report Scam
Forex Trading Review
Home»News and Views»OpenSea patches vulnerability that potentially exposed users’ identities
News and Views

OpenSea patches vulnerability that potentially exposed users’ identities

March 13, 2023Updated:March 13, 2023No Comments
Share
Facebook Twitter LinkedIn Pinterest Email

 

 

Nonfungible token marketplace OpenSea has reportedly patched a vulnerability that, if exploited, could have exposed identifying information about its anonymous users. 

In a March 9 blog post blog, cybersecurity firm Imperva detailed how it discovered the vulnerability, which it claimed could deanonymize OpenSea users “by linking an IP address, a browser session, or an email in certain conditions” to an NFT.

As the NFT corresponds to a cryptocurrency wallet address, a user’s real identity could be revealed from the information gathered and linked to the wallet and its activity, Imperva explained.

Imperva Red Team discovered a cross-site search vulnerability affecting the #NFT marketplace #OpenSea.

This vulnerability allows for the deanonymization of users, potentially revealing a user’s identity. https://t.co/nGQWceeGEc

— Imperva (@Imperva) March 9, 2023

The exploit is understood to have taken advantage of a cross-site search vulnerability. Imperva claimed OpenSea had misconfigured a library that resizes webpage elements that load HTML content from elsewhere that are typically used to place ads, interactive content, or embedded videos.

As OpenSea didn’t restrict this library’s communications, exploiters could use the information it broadcasts as an “oracle” to narrow down when searches return no results as the webpage would be smaller.

Imperva detailed that an attacker would send their target a link through email or SMS, which if clicked “reveals valuable information, such as the target’s IP address, user agent, device details, and software versions.”

image
Screenshot of OpenSea’s front page. Source: OpenSea

The attacker would then use OpenSea’s vulnerability to extract the NFT names of their target and associate the corresponding wallet address with identifying information such as an email or phone number which was sent the original link.

Imperva said OpenSea “quickly addressed the issue” and properly restricted the library’s communications, reporting that the platform “was no longer at risk of such attacks.”

Related: Security team creates dashboard to detect potential NFT hacks in OpenSea

Users of the platform have long been victims of attacks that mimic OpenSea’s functions to undertake exploits, such as phishing websites that resemble the platform or signature requests appearing to originate from OpenSea.

OpenSea itself has faced criticism for its platform security due to a major phishing attack in February 2022 that resulted in over $1.7 million worth of NFTs being stolen from users.

As for the recent patch, it’s unknown how long it existed or if any users had been affected by the exploit.

OpenSea did not immediately respond to Cointelegraph’s request for comment.

 

 

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Michael Esber
  • Website

Related Posts

FTX seeks to claw back $460M from Bankman-Fried-backed VC firm

March 23, 2023

‘How did this happen’ — Powell says Fed stumped over the collapse of SVB

March 23, 2023

CFTC’s tech committee gathered in DC to talk DeFi — Here’s what was discussed

March 23, 2023

Coinbase CEO on its Wells notice: SEC is like soccer referees in a game of pickleball

March 23, 2023
Add A Comment

Leave A Reply Cancel Reply

Top Posts

Subscribe to Updates

Get the latest creative news from xBTCh for Forex and Crypto Alerts and Reviews

Your source for the serious news on crypto and forex. This website is crafted specifically to empower the consumer to exchange ideas and information freely, and anonymously.

We're social. Connect with us:

Facebook Twitter Instagram YouTube
Top Insights

Škoda Investice platform Review 2023 – Doubtful service attracts dizzying earnings, it’s a scam

March 23, 2023

REVOLUT Review 2023: Experience, Fees, Card, Buy Stocks & Cryptocurrencies, Discussions, Scam

March 23, 2023

FTX seeks to claw back $460M from Bankman-Fried-backed VC firm

March 23, 2023
Get Informed

Subscribe to Updates

Get the latest creative news from xBTCh for Forex and Crypto Alerts and Reviews

Forex Trading Review
Facebook Twitter Instagram
  • Home
  • About us
  • Privacy Policy
  • Terms of Service
  • Report Scam
  • Get In Touch
© 2023 FTR. Designed by FTR Research LLC.

Type above and press Enter to search. Press Esc to cancel.