NEAR Protocol Reports A Breach Of Customer Wallet-Related Email And SMS Data

A Layer 1 blockchain called NEAR Protocol informed consumers that SMS and email data used as recovery options in its basic wallet service had been compromised in June. According to a recent report from NEAR, the problem was fixed before any damage was done.

NEAR Protocol Reports A Breach Of Customer Wallet-Related Email And SMS Data

Users can add recovery options, such as email addresses or phone numbers, to their crypto wallet accounts by using the wallet service provided by NEAR Protocol at wallet.near.org. Sensitive information was unintentionally made available to a third party due to a system bug.

In order to stop the breach from posing a threat to user privacy or financial security, NEAR said that it was able to promptly address the situation by erasing access to the data from the third party or its own personnel.

 “The wallet team immediately remediated the situation, scrubbed all sensitive data, and identified any personnel who could have had the ability to access this data” the team said. 

A web3 security auditing company called Hacxyk, which received a $50,000 reward, discovered the flaw on June 6. But up until recently, the NEAR Protocol team had kept the details to themselves.

NEAR Protocol’s use of the analytics provider Mixpanel

NEAR Protocol Reports A Breach Of Customer Wallet-Related Email And SMS Data

The third party, according to Hacxyk, was NEAR’s use of the analytics provider Mixpanel. Hacxyk likened the situation to the current Slope Wallet problem, in which wallet information was unintentionally sent to a central server. Additionally, it said that private keys may have also been compromised in the instance of NEAR.

“We believe the nature is very similar to the recent Slope wallet hack on Solana. In short, the seed phrases were unknowingly leaked to the third party Mixpanel, an analytics service, when users chose email/SMS as the seed phrase recovery method. This means users’ seed phrases are stored into Mixpanel’s server” Hacxyk said.

The NEAR Protocol stated that it no longer permits users to create accounts utilizing email or SMS for account recovery as a security measure. It also suggested that customers “rotate their keys” or add a hardware wallet, like as Ledger, if they had previously used email or SMS recovery alternatives with their NEAR wallet.

According to Hacxyk, NEAR wallets’ wallet account model differs slightly from Ethereum’s. A crypto account may have several keysets with various levels of access. NEAR instructs users to revoke any possibly compromised keysets and add new ones in their place by rotating private keys.

DISCLAIMER: The Information on this website is provided as general market commentary and does not constitute investment advice. We encourage you to do your own research before investing.

Join CoinCu Telegram to keep track of news: https://t.me/coincunews

Follow CoinCu Youtube Channel | Follow CoinCu Facebook page

Annie

CoinCu News

Annie

Championing positive change through finance, I've dedicated over eight years to sustainability and environmental journalism. My passion lies in uncovering companies that make a real difference in the world and guiding investors towards them. My expertise lies in navigating the world of sustainable investing, analyzing ESG (Environmental, Social, and Governance) criteria, and exploring the exciting field of impact investing. "Invest in a better future," I often say. That's the driving force behind my work at Coincu – to empower readers with knowledge and insights to make investment decisions that create a positive impact.

Recent Posts

Zircuit Launches ZRC Token: Pioneering the Next Era of Decentralized Finance

George Town, Grand Cayman, 22nd November 2024, Chainwire

3 minutes ago

Inflation Warning By Vanguard Amid Tariffs And Labor Issues

Inflation Warning by Vanguard highlights risks during Trump’s term, citing tariffs and tighter labor markets…

19 minutes ago

Clanker Token Trading Volume Hits $59.8 Million High

Clanker token trading volume hit $59.8M on Nov 21, accounting for 14.75% of PumpFun. Fee…

47 minutes ago

Bitcoin Spot ETF Inflows Hit $1 Billion Led By BlackRock

Bitcoin Spot ETF inflows hit $1.005B on Nov 21, led by BlackRock’s $608M and Fidelity’s…

1 hour ago

New York Techie Bagged $72M from $15K Investment in Ethereum — Here’s How BlockDAG Can Offer Similar Jackpot

Discover the success story of a New York tech entrepreneur who made $72M from a…

2 hours ago

Best Altcoins to Buy Today: Qubetics Rides 1000x Potential to Hit $2.6M, Ethereum Stays Rangebound, Tron USDT Transactions Hit $52B

Discover the best cryptos to buy and hold today: Qubetics leads with 1000x potential, Ethereum…

3 hours ago

This website uses cookies.