NEAR Protocol Reports A Breach Of Customer Wallet-Related Email And SMS Data

A Layer 1 blockchain called NEAR Protocol informed consumers that SMS and email data used as recovery options in its basic wallet service had been compromised in June. According to a recent report from NEAR, the problem was fixed before any damage was done.

NEAR Protocol Reports A Breach Of Customer Wallet-Related Email And SMS Data

Users can add recovery options, such as email addresses or phone numbers, to their crypto wallet accounts by using the wallet service provided by NEAR Protocol at wallet.near.org. Sensitive information was unintentionally made available to a third party due to a system bug.

In order to stop the breach from posing a threat to user privacy or financial security, NEAR said that it was able to promptly address the situation by erasing access to the data from the third party or its own personnel.

 “The wallet team immediately remediated the situation, scrubbed all sensitive data, and identified any personnel who could have had the ability to access this data” the team said. 

A web3 security auditing company called Hacxyk, which received a $50,000 reward, discovered the flaw on June 6. But up until recently, the NEAR Protocol team had kept the details to themselves.

NEAR Protocol’s use of the analytics provider Mixpanel

NEAR Protocol Reports A Breach Of Customer Wallet-Related Email And SMS Data

The third party, according to Hacxyk, was NEAR’s use of the analytics provider Mixpanel. Hacxyk likened the situation to the current Slope Wallet problem, in which wallet information was unintentionally sent to a central server. Additionally, it said that private keys may have also been compromised in the instance of NEAR.

“We believe the nature is very similar to the recent Slope wallet hack on Solana. In short, the seed phrases were unknowingly leaked to the third party Mixpanel, an analytics service, when users chose email/SMS as the seed phrase recovery method. This means users’ seed phrases are stored into Mixpanel’s server” Hacxyk said.

The NEAR Protocol stated that it no longer permits users to create accounts utilizing email or SMS for account recovery as a security measure. It also suggested that customers “rotate their keys” or add a hardware wallet, like as Ledger, if they had previously used email or SMS recovery alternatives with their NEAR wallet.

According to Hacxyk, NEAR wallets’ wallet account model differs slightly from Ethereum’s. A crypto account may have several keysets with various levels of access. NEAR instructs users to revoke any possibly compromised keysets and add new ones in their place by rotating private keys.

DISCLAIMER: The Information on this website is provided as general market commentary and does not constitute investment advice. We encourage you to do your own research before investing.

Join CoinCu Telegram to keep track of news: https://t.me/coincunews

Follow CoinCu Youtube Channel | Follow CoinCu Facebook page

Annie

CoinCu News

Annie

Championing positive change through finance, I've dedicated over eight years to sustainability and environmental journalism. My passion lies in uncovering companies that make a real difference in the world and guiding investors towards them. My expertise lies in navigating the world of sustainable investing, analyzing ESG (Environmental, Social, and Governance) criteria, and exploring the exciting field of impact investing. "Invest in a better future," I often say. That's the driving force behind my work at Coincu – to empower readers with knowledge and insights to make investment decisions that create a positive impact.

Recent Posts

Bitcoin Rallies 12,464% To Outshine Amazon And Google, Experts Reveal The Next BTC

Bitcoin (BTC) has outperformed major tech stocks in the past decade, and this growth translates…

2 mins ago

Is DWF Labs Market Manipulation Being Covered By Binance, Or Is There An Important Secret?

Allegations of DWF Labs market manipulation surface at Binance after the dismissal of an internal…

1 hour ago

Bitcoin Mining Difficulty Sees Sharpest Drop Since December 2022

Bitcoin mining difficulty dropped by 5.63% to 83.15 T, marking the largest decrease since December…

2 hours ago

AIGOLD Goes Live, Introducing the First Gold Backed Crypto Project

George Town, Cayman Islands, May 8th, 2024, ChainwireAIGOLD is pleased to announce the launch of…

3 hours ago

ETHPrague 2024: Shaping the Future of Ethereum Beyond DeFi Boundaries!

ETHPrague 2024 is breaking new ground by shifting its attention away from get-rich-quick schemes and…

8 hours ago

Polygon (MATIC) Deposits Now Supported at Crypto.Games Casino!

Crypto.Games, an online cryptocurrency casino established in 2020 and renowned for its innovative approach to…

8 hours ago

This website uses cookies.