Over 7 million email addresses were compromised in a data leak incident at OpenSea's provider in 2022, and have recently been "fully disclosed" online. This disclosure is opening up many risks of exploitation by Scammer groups. SlowMist's security director, "23pds", warned of this risk in a post on X on January 13.
"Do you remember the attack on OpenSea's email service provider in 2022, which led to the email leak? Currently, the leaked email list has been fully disclosed after multiple distributions," 23pds shared on X.
According to 23pds's explanation, although the attack occurred in June 2022, the data had not been disclosed until recently. This increases the risk of all criminal groups using the information to carry out fraudulent activities.
"The volume of leaked data is up to 7 million, including a large number of email addresses of people active in the international crypto industry, including many celebrities, companies and key opinion leaders (KOLs)," 23pds said.
OpenSea, one of the world's largest NFT trading platforms, first announced the data leak incident on June 29, 2022, after discovering that an employee of Customer.io - their email automation platform - had disclosed the customer email list to a third party.
"For anyone who has shared their email with OpenSea in the past, we advise you to assume you have been impacted. We are currently working with Customer.io on the investigation and have reported the incident to the authorities," OpenSea said at the time.