• News
    • Bitcoin
    • Altcoins
  • Regulation
  • Blockchain
  • NFT
    • NFT News
    • Collectibles
    • Crypto Art
    • Gaming
    • Play2Earn
  • Metaverse
  • Learn
  • Market Cap
What's Hot

CFTC Goes After Binance and Changpeng Zhao With Lawsuit, Bitcoin (BTC) and Crypto Markets Get Rocked

2023-03-27

Tezos releases new update for Mumbai Protocol- Will XTZ benefit?

2023-03-27

What is NFT Finance (NFTfi)?

2023-03-27
Facebook Twitter Instagram
Monday, March 27
Facebook Twitter Instagram
Patrol Crypto
  • News
    • Bitcoin
    • Altcoins
  • Regulation

    CFTC Goes After Binance and Changpeng Zhao With Lawsuit, Bitcoin (BTC) and Crypto Markets Get Rocked

    2023-03-27

    Justin Sun’s US fraud charges could hamper Huobi’s license application in Hong Kong

    2023-03-27

    Coinbase Executive Says US Government Squandering Lead in Technology With Lack of Crypto Regulatory Clarity

    2023-03-27

    Crypto Analyst Nicholas Merten Says Fed Money Printing Won’t Spark New Bitcoin (BTC) Rally – Here’s Why

    2023-03-26

    US Prosecutors Slam Terra (LUNA) Founder Do Kwon With Eight Counts of Fraud for 2022 Crypto Collapse

    2023-03-26
  • Blockchain

    Ethereum L2 Base Proposed 4 Areas Of Focus For Builders

    2023-03-25

    Ethereum Solution To Upgrade Transaction Speed With Saving Gas Fees

    2023-03-24

    zkSync Collaborates with Web3 Gaming Platforms

    2023-03-24

    SWIFT Unveils Results of Blockchain Pilot – Is XRP Involved?

    2023-03-24

    Shibarium Testnet Chain ID Officially Changed

    2023-03-24
  • NFT
    • NFT News
    • Collectibles
    • Crypto Art
    • Gaming
    • Play2Earn
  • Metaverse

    Animoca Denies $200M Metaverse Fund Cut

    2023-03-27

    Metaverse Trading Hits All-Time High

    2023-03-24

    Exploring the Metaverse: A Guide to Investing in Metaverse Stocks

    2023-03-20

    A Guide to Virtual Land Staking in the Metaverse

    2023-03-20

    Nissan Doubles Down on Web3 Innovation

    2023-03-13
  • Learn

    Chart Patterns Cheat Sheet For Technical Analysis

    2023-03-21

    Best NFT Wallets in 2023

    2023-03-21

    Top 10 Best Ethereum Wallets 2023

    2023-03-18

    What are Dapps (Decentralized Applications) Crypto?

    2023-03-17

    How to Short Sell Bitcoin

    2023-03-17
  • Market Cap
Patrol Crypto
Home»NFT»OpenSea patches vulnerability that potentially exposed users’ identities
NFT

OpenSea patches vulnerability that potentially exposed users’ identities

2023-03-13No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Nonfungible token marketplace OpenSea has reportedly patched a vulnerability that, if exploited, could have exposed identifying information about its anonymous users. 

In a March 9 blog post blog, cybersecurity firm Imperva detailed how it discovered the vulnerability, which it claimed could deanonymize OpenSea users “by linking an IP address, a browser session, or an email in certain conditions” to an NFT.

As the NFT corresponds to a cryptocurrency wallet address, a user’s real identity could be revealed from the information gathered and linked to the wallet and its activity, Imperva explained.

Imperva Red Team discovered a cross-site search vulnerability affecting the #NFT marketplace #OpenSea.

This vulnerability allows for the deanonymization of users, potentially revealing a user’s identity. https://t.co/nGQWceeGEc

— Imperva (@Imperva) March 9, 2023

The exploit is understood to have taken advantage of a cross-site search vulnerability. Imperva claimed OpenSea had misconfigured a library that resizes webpage elements that load HTML content from elsewhere that are typically used to place ads, interactive content, or embedded videos.

As OpenSea didn’t restrict this library’s communications, exploiters could use the information it broadcasts as an “oracle” to narrow down when searches return no results as the webpage would be smaller.

Imperva detailed that an attacker would send their target a link through email or SMS, which if clicked “reveals valuable information, such as the target’s IP address, user agent, device details, and software versions.”

Screenshot of OpenSea’s front page. Source: OpenSea

The attacker would then use OpenSea’s vulnerability to extract the NFT names of their target and associate the corresponding wallet address with identifying information such as an email or phone number which was sent the original link.

See also  Amazon NFT Platform Is Gamechanger

Imperva said OpenSea “quickly addressed the issue” and properly restricted the library’s communications, reporting that the platform “was no longer at risk of such attacks.”

Related: Security team creates dashboard to detect potential NFT hacks in OpenSea

Users of the platform have long been victims of attacks that mimic OpenSea’s functions to undertake exploits, such as phishing websites that resemble the platform or signature requests appearing to originate from OpenSea.

OpenSea itself has faced criticism for its platform security due to a major phishing attack in February 2022 that resulted in over $1.7 million worth of NFTs being stolen from users.

As for the recent patch, it’s unknown how long it existed or if any users had been affected by the exploit.

OpenSea did not immediately respond to Cointelegraph’s request for comment.

Source link

exposed identities OpenSea patches Potentially Users vulnerability
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

y00ts forms a link from Solana to Polygon & eases the user experience

2023-03-27

How to buy NFTs without owning crypto

2023-03-27

ApeCoin Community Rejects Proposal for Two New NFT Collection Series

2023-03-27

Luxury Giant Gucci Teams Up With Yuga Labs To Develop Web3

2023-03-27
Add A Comment

Leave A Reply Cancel Reply

Top Posts

Metaverse not the endgame, but ‘ongoing digital transformation’: Davos 2023

2023-01-19

Evaluating Bitcoin’s price trajectory if regulators dial-up heat on crypto

2023-02-04

Bitcoin [BTC]: What you should expect following 2023’s 23% rally

2023-01-18

Subscribe to Updates

Get the latest news and Update from Patro Crypto about Crypto, Metaverse, NFT and more.

About
About

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Cryptocurrencies, NFT, Metaverse and more.

We're social. Connect with us:

Facebook Twitter Instagram Pinterest YouTube
Top Insights

CFTC Goes After Binance and Changpeng Zhao With Lawsuit, Bitcoin (BTC) and Crypto Markets Get Rocked

2023-03-27

Tezos releases new update for Mumbai Protocol- Will XTZ benefit?

2023-03-27

What is NFT Finance (NFTfi)?

2023-03-27
Get Informed

Subscribe to Updates

Get the latest news and Update from Patro Crypto about Crypto, Metaverse, NFT and more.

  • Contact
  • Terms & Conditions
  • Privacy Policy
  • DMCA
© 2023 Patrolcrypto.com - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

  • JDBJDB(JDB)$0.021575-0.61%
  • bitcoinBitcoin(BTC)$27,050.00-2.93%
  • ethereumEthereum(ETH)$1,708.86-3.14%
  • USDEXUSDEX(USDEX)$1.08-0.31%
  • tetherTether(USDT)$1.00-0.02%
  • binancecoinBNB(BNB)$307.28-6.28%
  • usd-coinUSD Coin(USDC)$1.00-0.06%
  • rippleXRP(XRP)$0.4744636.12%
  • cardanoCardano(ADA)$0.342570-3.38%
  • dogecoinDogecoin(DOGE)$0.072813-1.63%