/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

OpenSea warns all its users of email phishing attempts after an employee at email vendor Customer.io downloaded and sent email details to an external party

Rita Liao / TechCrunch : Source: OpenSea Blog .

TechCrunch Rita Liao

Context & Ripple Effects

OpenSea had already confronted phishing that led users to sign malicious smart contracts and lose NFTs in a targeted phishing campaign. The Customer.io incident gives attackers a broader route to impersonate OpenSea through email, adding to a trust problem the company had been trying to address amid complaints about stolen and plagiarized NFTs.

The earlier phishing episode was followed by a drop in OpenSea trading activity, making user confidence commercially consequential rather than merely a security issue. The exposure also places a third-party email provider inside OpenSea's security perimeter.

First-order effects

  • OpenSea users must treat messages purporting to come from the marketplace as potential phishing attempts after their email details were sent externally.
  • Customer.io becomes directly accountable to OpenSea for an employee action that exposed a channel used for customer communications.

Second-order effects

  • OpenSea must devote more customer-support and trust efforts to distinguishing legitimate notices from impersonation attempts, following its earlier steps to improve trust around stolen and plagiarized NFTs.
  • Email-service vendors serving marketplaces face greater pressure to limit employee access to customer data, because a vendor-side lapse can create platform-level fraud risk.

Third-order effects

  • The incident points to ecosystem cyber defense becoming a core marketplace function: a platform's user protection depends on the controls of communication and other service providers, not only on its own product security.
  • Repeated phishing-linked losses and trust complaints could make vendor governance a competitive differentiator for NFT marketplaces as users weigh where to transact.

The trend: Digital marketplaces are treating third-party service providers as part of their fraud and security perimeter, especially where compromised communications can trigger asset theft.

Discussion

  • @opensea @opensea on x
    An employee of our email vendor, https://t.co/..., misused their employee access to download & share email addresses with an unauthorized external party. Email addresses provided to OpenSea by users or newsletter subscribers were impacted. https://opensea.io/...
  • @opensea @opensea on x
    1) We will ONLY send you emails from the domain ‘ https://opensea.io/.’ Be aware of attempts to impersonate OpenSea through slight variations of our domain name, like below: https://twitter.com/...
  • @joetidy Joe Tidy on x
    “If you have shared your email with OpenSea in the past, you should assume you were impacted.” This could lead to many many lost apes. But seriously - could be bad. https://twitter.com/...
  • @cz_binance @cz_binance on x
    Watch out for Phishing emails. Ideally, use a different email address for each platform you use. ie, use an email forwarding service. This way, if you get a phishing email, you know who leaked it. » OpenSea Reports Email Data Breach https://www.coindesk.com/...
  • @irinaheaver @irinaheaver on x
    An employee of @opensea contractor sells all our emails Good job 👏 🤨 https://twitter.com/...
  • @ahiddensociety @ahiddensociety on x
    BREAKING: An employee for the email provider of @opensea has sold a full list of all accounts associated with their #NFT platform. While we don't know the extent of the damage, this isn't ideal for #Web3. Watch for phishing scams & read more here. 👇 https://opensea.io/... https:/…
  • @alexhern @alexhern on x
    WARNING: you may receive an email from someone trying to I sell you a picture of a monkey for more than a million dollars. THIS IS A SCAM DO NOT CLICK THE LINK https://twitter.com/...
  • @gcluley Graham Cluley on x
    NFT marketplace OpenSea warns of data breach. “If you have shared your email with OpenSea in the past, you should assume you were impacted.” https://grahamcluley.com/...
  • @opensea @opensea on x
    2) NEVER download anything from an OpenSea email. 3) Check the URL of any page linked in an OpenSea email. We will only include hyperlinks to ‘ https://email.opensea.io/.’ URLs. 4) NEVER share your seed phrase with anyone - we'll never ask for it.
  • @eclecticmethod @eclecticmethod on x
    OpenSea has decentralized our email addresses
  • @screentimes @screentimes on x
    dear opensea, a $30k airdrop to every user could make everyone forget about this small inconvenience. it would reignite the fire in buyers hearts. tens of thousands of families would benefit from such great airdrop. “the greatest airdrop ever!!”, “the metaverse dream is alive!!” …
  • @officer_cia @officer_cia on x
    FYI All @opensea users emails are now public, be extremely accurate when interacting with emails received from https://opensea.io/ 🚨 1 - hackers may use email spoofing; 2 - hackers may use email appender https://twitter.com/...; 3 - You may get an IP-logger/canary token. https://…
  • @opensea @opensea on x
    5) We'll NEVER ask you to sign wallet transactions from our emails. 6) Always review anything you sign with your wallet carefully. When in doubt, do not sign! 7) Do not interact with emails & files sent by strangers.
  • @ryancarson Ryan Carson on x
    😬 stay safe y'all! https://twitter.com/...
  • @troyhunt Troy Hunt on x
    😮 “our email delivery vendor, misused their employee access to download and share email addresses” https://opensea.io/...
  • @punk6529 @punk6529 on x
    be careful on emails purporting to be from opensea https://twitter.com/...
  • @opensea @opensea on x
    https://customer.io/'s investigation is ongoing, and we've reported this incident to law enforcement. Read more in our blog: https://opensea.io/...