Did you use OpenSea? Be careful, you could be a victim of phishing

Foto del autor

By TP

The leak occurred in 2022, but the addresses were recently disclosed. The address of the former president of Binance, “CZ”, appeared in the list of leaked emails. According to a researcher at SlowMist, a cybersecurity company founded in 2018, users of OpenSea, the popular NFT marketplace, could be targeted by phishing attacks. The leak of data containing users' emails occurred in 2022. The researcher, whose pseudonym is im23pds on the social network

The leaked email addresses have already been made public after multiple broadcasts. Be aware of the risks associated with phishing emails and other potential cyberattacks! im23pds, SlowMist researcher.

The amount of data leaked at the time would have reached the sum of 7 million, among which are included “a large number of emails from cryptocurrency professionals abroad, including many well-known people, companies and key opinion leaders (KOLs) in the industry,” says the researcher. Those affected would not have been just ordinary users, but also well-known members of the bitcoin and cryptocurrency industry, as Chang Peng Zhao, who, as BitcoinDynamic reported, is the former executive president of Binance.

Phishing is one of the most common ways to be scammed on the internet. Source: Social Network That is, from fraudulent actors sending emails disguised as OpenSea agents or simulating automated attention-grabbing messages of NFT market users. A user comments on the social network The author of this article received an automated message of the same style, according to which one of his listed NFTs “has generated significant interest.” However, at the time of writing, it does not own any NFTs listed for auction or sale on that NFT marketplace.

Probably fraudulent message from OpenSea impersonators. Source: Gmail These emails have malicious attachments or links that lead to fraudulent pages that imitate the NFT market and that they could request the user's real credentials, such as email and password. Also asking the user to connect their wallet to the site through a smart contract, causing them to grant access to their private funds without knowing it.

Protect yourself from phishing with these tips

An effective way to detect fraudulent emails from impersonators is by checking the domain names of the sender email. Generally, phishing domains are not suspicious, and imitate legitimate ones with slight variations, adding or omitting a single letter or number. For example, instead of “BitcoinDynamic.com”, you could use “criptonoticiass”. Phishing emails can also come from generic domains such as “@gmail.com” or “@yahoo.com”, when you would expect them to be official corporate domains. For example: autor@BitcoinDynamic.com. On other occasions, the domain names of the fraudulent emails are a disorganized sequence of alphanumeric characters, as shown in the following image:

One way to detect phishing is to take a look at the domain name of the sender. Source: Gmail A final useful feature to know when detecting phishing emails is that they often create a sense of urgency or fear so that the recipient acts quickly and without thinking.

0