Users of the major nonfungible token (NFT) marketplace OpenSea have said they are being targeted with a new email phishing attack, and have received emails containing malicious links from attackers posing as the marketplace itself.
One OpenSea developer took to X (formerly Twitter) on Nov. 13 to report receiving a phishing attempt to an email strictly dedicated to their OpenSea Application Programming Interface (API) key. “In other words, dev contacts have been exfiltrated from OpenSea and are the real target in this campaign,” the poster said.
The social media report came in response to OpenSea’s insistence that the platform has not been hacked and urging users not to click on links they don’t trust.
Correct- there is no smart contract vuln. But unfortunately for @opensea I just received a phishing attempt, to an email that was strictly dedicated to my OpenSea API key. In other words, dev contacts have been exfiltrated from OpenSea and are the real target in this campaign https://t.co/GD4UgwWIrx pic.twitter.com/rtyUJBMlwl
— Quantity (@quantity) November 13, 2023
“Haven’t used OpenSea for years and all of a sudden, I keep getting emails talking about my NFT listings getting offers,” the poster wrote, adding that all the vulnerable links were trying to direct the reader to install a malicious app.
“Right now I’m getting 3-4 scam/phishing emails a day which is crazy since I got zero just a few weeks ago,” the Redditor wrote, adding:
“So my question is did something new happen to OpenSea. The email address of mine they are hitting is one I created specifically for OpenSea so not concerned but I know OpenSea had hacks previously. Are they just now hitting up my email or is there a new one?”
The news comes a few weeks after one of OpenSea’s third-party vendors experienced a security incident that exposed information related to user API keys. OpenSea reported the breach in a notification email to affected users in late September 2023, stating that user emails and developer API keys may have been leaked due to the attack.
Choose your third party well…
Opensea posted that a vendor was attacked, resulting in the leak of developers’ API keys!
Get advice from a professional security consultant about the safety of the third party before choosing. E.g. @SlowMist_Team pic.twitter.com/jcBJ9IaAEN
— 23pds (@IM_23pds) September 23, 2023
OpenSea users have received phishing emails previously. In February 2022, OpenSea officially confirmed that its platform faced a phishing attack from outside the OpenSea website and urged users to stay away from clicking on any links in the emails. The firm was also investigating rumors of an exploit associated with OpenSea-related smart contracts.
This attack is yet another reminder for the cryptocurrency community to stay vigilant when receiving emails from service providers. To avoid a phishing hack, users should be cautious of the email sender’s authenticity and the associated links. Users should also remember that crypto firms never ask their users for personal data like wallet addresses or private keys.