3 Million CoinMarketCap Emails Surface Online But ‘No Trace’ of Security Breach
Yesterday, a site that scans the internet for data breaches reported that 3.1 million email addresses had been stolen from CoinMarketCap’s database. Have I Been Pwned discovered on October 12 that emails used on the cryp...
Yesterday, a site that scans the internet for data breaches reported that 3.1 million email addresses had been stolen from CoinMarketCap’s database.
Have I Been Pwned discovered on October 12 that emails used on the crypto price aggregator site were being traded on a hacking forum. The suspected leak does not contain passwords.
New breach: 3.1M email addresses from CoinMarketCap were found being traded this month. CMC have advised there is "a correlation with our subscriber base", but are yet to identify the source of the data. 99% were already in @haveibeenpwned https://t.co/LGaAnj1hUA
— Have I Been Pwned (@haveibeenpwned) October 22, 2021
But CoinMarketCap said today in a blog post that the leak “did not come from CoinMarketCap servers.” The company, which is a subsidiary of Binance, said it found “no trace of any security breach.”
CoinMarketCap reportedly told Have I Been Pwned there is “a correlation with our subscriber base,” but that 99% of the emails were already listed in the data breach site, meaning that they had already been exposed by earlier breaches on other sites.
“As no passwords are included in the data we have seen, we believe that it is most likely sourced from another platform where users may have reused passwords across multiple sites,” said CoinMarketCap.
CoinMarketCap believes that the attacker sold a list of leaked emails and compared it with other collections of leaked information to verify the emails.
“This is how the list of emails that claims to be from CoinMarketCap looks real — it’s because it’s a ‘cleaned’ email dataset from the Dark Web that has occurred in previous leaked email sets totally unrelated to CoinMarketCap,” said CoinMarketCap.
If your email is part of it, expect to get a lot of spam from crypto scams. Also, if you use that email for any exchange accounts, remove it asap and use another.
Stay safe guys
— Coin Bureau (guy.eth) (@coinbureau) October 23, 2021
CoinMarketCap’s parent company, Binance, was hacked in 2019. Hackers accessed important information, such as two-step authentication data and API keys, and stole 7,000 Bitcoin. Hacks are rife on Binance’s blockchain, the Binance Smart Chain.
On Wednesday, decentralized finance (DeFi) protocol PancakeHunny was exploited for about $1.9 million after attackers used flash loans to manipulate the price of a liquidity pool.
Original source
Read on DecryptRelated market context
Millions of EU crypto users face exchange cutoff as MiCA deadline hits in days
On July 1, 2026, the temporary permission that lets crypto companies keep operating in Europe while they wait for a proper MiCA li...
$557M Frozen, Then Refunded: Binance’s SpaceX IPO Chaos Rocks Tokenized Stocks Market
Key Takeaways: Following the failure in SpaceX tokenized IPOs, Binance, Bitget Wallet and MEXC have withdrawn their plans. Binance...
Coinbase Quantum Report Warns Millions Of Bitcoin Could Face Future Security Risks
TL;DR Coinbase’s Quantum Advisory Council published a report on post-quantum migration and abandoned coins. The report estimates t...
Spot Bitcoin ETFs Snap Five-Day Outflow Streak With $85.8 Million Inflows
TL;DR Spot Bitcoin ETF products returned to net inflows after five straight days of outflows. The reported Friday total was $85.8...
Tether USDT Briefly Overtakes Ethereum in Market Cap: A $187B Wake-Up Call
For a few hours, earlier this week, Tether USDT stablecoin held a higher market cap than Ethereum, the first time that has happene...
Bitcoin price challenges $64,000 weekend wall – needing a breakout or risk a deeper correction
Bitcoin reclaimed $64,000 on June 12 and touched an intraday high of $64,301 in the same session that spot ETF flows finally flipp...