BlockNews.com
  • Crypto
  • NFT
  • Metaverse
  • DeFi
  • Business
  • Technology
  • Opinion
  • Guides
No Result
View All Result
SUBSCRIBE
BlockNews.com
  • Crypto
  • NFT
  • Metaverse
  • DeFi
  • Business
  • Technology
  • Opinion
  • Guides
No Result
View All Result
BlockNews.com
No Result
View All Result
Home Business

OpenSea Found a Vulnerable Spot that Could Endanger Users’ Identities and Quickly Fixed it

BlockNews Team by BlockNews Team
March 14, 2023
in Business, Media, NFT, Social
Reading Time: 3 mins read
A A
opensea
1
SHARES
10
VIEWS
Share on TwitterShare on Reddit
  • Vulnerabilities in its system almost endanger OpenSea’s users. 
  • A cybersecurity firm, Imperva, details how the vulnerability in OpenSea was created. 
  • OpenSea acts fast in the face of possible chaos. 

A cybersecurity firm named Imperva reportedly found a vulnerable spot in OpenSea that could potentially cause a leak in customer information.

You might also like

Mark Cuban Slams Gold Hoarders, Defends Bitcoin

Crypto Exchanges Benefit from US Banking Crisis: JPMorgan

The UAE Central Bank Signs Deal for CBDC Strategy

NFT marketplace, OpenSea, has patched up the vulnerability, which, if left for too long, could expose the identity of its users, like their phone numbers, Email addresses, and other information that could have stripped them of their anonymity.

The cybersecurity firm that discovered the vulnerability detailed how it found the leak in a blog post last week, stating that the users of NFT marketplace OpenSea could be compromised if an IP address was linked or a browser session or an email in certain circumstances to an NFT.

NFTs are also linked to a crypto wallet address, and a user’s real identity could be quickly revealed from the information gathered and could then be linked to the wallet and its activity.

Imperva claims that the vulnerability was gotten from taking advantage of a cross-site search vulnerability, and OpenSea had allegedly misconfigured a library that helps in resizing webpage elements that also help in loading HTML contents from another source is typically used to place ads, interactive content, and embedded videos.

OpenSea decision to not restrict the library’s communications could allow exploiters to use the information it broadcasts as an oracle to aid in narrowing down when searches return no results, as it would make the webpage smaller.

The cybersecurity firm also added that an attacker could send their target link with the use of sms or emails, which, if clicked by a user, could reveal important information on the user, like their IP address, user agent software versions, and other things like their device details.

When all these are obtained, an attacker could then go ahead to make use of OpenSea’s vulnerability to exploit and extract the NFT identities of their targets and associate them with their wallet addresses with identifying information like their email or phone numbers which were previously obtained through the link clicked by the user.

OpenSea quickly addressed the vulnerability in their system and patched it up by properly restricting communication for the library and ensuring that the NFT marketplace was safe from the risk of such attacks.

OpenSea’s users have previously been victims of copycat attacks that mimic OpenSea’s functionality to exploit users with phishing websites that look precisely like OpenSea or by sending in Signature requests that seem like they originated from OpenSea.

OpenSea’s quick response to the information of a vulnerability in its system saved it from the chaos that could have ensued if exploiters succeeded in using users’ data to access their wallets. It would have led to another attack on users and created another wave of hacks in the web three space.

Conclusion

OpenSea had previously faced criticism for its lack of security when a significant phishing attack in February last year wiped over $1.7 million worth of NFTs from its users.

It is unclear if this recent vulnerability resulted in any loss for users, but OpenSea quickly fixed the vulnerability.

Tags: BusinessNFTNFT MarketplaceNFTsopensea
TweetShareShare

Recommended For You

Mark Cuban Slams Gold Hoarders, Defends Bitcoin

by BlockNews Team
March 27, 2023
0
mark cuban

Mark Cuban and Bill Maher hold opposing views on Bitcoin vs gold investment Cuban argues in favor of Bitcoin's digital ledger and stored value, while Maher prefers gold's...

Read more

Crypto Exchanges Benefit from US Banking Crisis: JPMorgan

by BlockNews Team
March 27, 2023
0
JP Morgan

The collapse of three major banks in the US may have opened up an opportunity for crypto exchanges all over the world, according to JPMorgan Tether took the...

Read more

The UAE Central Bank Signs Deal for CBDC Strategy

by BlockNews Team
March 27, 2023
0
CBUAE

UAE to release a CBDC  and begin its first phase very shorty. The CBDC strategy was first unveiled in February as part of the central bank’s program to...

Read more

‘Surgical Removal’ of Crypto Will Only Weaken USD Dominance, Commentators Say

by BlockNews Team
March 27, 2023
0
crypto dominance

The US banking system will only become more isolated as a result of the surgical removal of cryptocurrencies, which will also damage the dollar's status as the world's...

Read more

Aéropostale’s Exciting Journey into the Metaverse: Introducing AeroPax and AeroWorld

by BlockNews Team
March 27, 2023
0
AeroWorld Aéropostale

Aéropostale launches AeroPax, a collection of 30,000 unique NFT avatars, in partnership with MetaversePlus, offering exclusive perks and access to the upcoming AeroWorld metaverse. The brand has planned...

Read more
Next Post
visa mastercard

Visa and Mastercard Continue Adding New Debit-Card Partnerships with Crypto Companies

Related News

FTX

Funds with FTX Exposure Have 7% to 12% AUM Trapped

November 19, 2022
Mailchimp Stops Its Services for Crypto Content Creators

Mailchimp Stops Its Services for Crypto Content Creators

August 16, 2022
Whatever Happened to Age of Rust? A 2022 Review

Whatever Happened to Age of Rust? A 2022 Review

June 9, 2022

Browse by Category

  • Breaking News
  • Business
  • Crypto
  • DeFi
  • Finance
  • Gaming
  • Guides
  • Investing
  • Media
  • Metaverse
  • NFT
  • Opinion
  • Politics
  • Social
  • Technology
  • Uncategorized
BlockNews.com

BlockNews.com brings you the most important Crypto and NFT news in the space.

CATEGORIES

  • Breaking News
  • Business
  • Crypto
  • DeFi
  • Finance
  • Gaming
  • Guides
  • Investing
  • Media
  • Metaverse
  • NFT
  • Opinion
  • Politics
  • Social
  • Technology
  • Uncategorized

RECENT POSTS

  • Mark Cuban Slams Gold Hoarders, Defends Bitcoin March 27, 2023
  • Crypto Exchanges Benefit from US Banking Crisis: JPMorgan March 27, 2023
  • The UAE Central Bank Signs Deal for CBDC Strategy March 27, 2023

© 2022 BlockNews.com - Crypto and NFT news website by JRNY Club.

No Result
View All Result
  • Home
  • Crypto
  • NFT
  • Metaverse
  • DeFi
  • Business
  • Technology
  • Opinion
  • Guides

© 2022 BlockNews.com - Crypto and NFT news website by JRNY Club.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?