More than 3 million email addresses belonging to CoinMarketCap users have been leaked on the Dark Web. The data aggregator confirmed that the leak was from its database, however, the passwords would not have been compromised.
CoinMarketCap users’ emails in the wild
Data aggregator CoinMarketCap, which is popular among cryptocurrency enthusiasts, has suffered a data leak that resulted in the disclosure of several million user emails.
According to Have I Been Pwned, 3.1 million emails (3,117,548) linked to CoinMarketCap accounts are reportedly for sale on hacking forums.
CoinMarketCap, acquired by Binance in April 2020, confirmed the information and explained that the list of leaked user accounts did indeed match its user base:
“CoinMarketCap has become aware that batches of data have appeared online claiming to be a list of user accounts. Although the data lists we saw were only email addresses, we found a correlation to our subscriber base.”
How the data was leaked is still unknown, but it reportedly took place on October 12, 2021. CoinMarketCap also explained that the hackers did not have access to account passwords and that the leak did not originate from those servers.
“We have found no evidence of a data leak from our own servers, we are actively investigating this matter and will update our users as soon as we have new information.”
Data leaks are common
Despite the lack of immediate risk, this leak nevertheless violates users’ privacy. It could also give malicious people the resources to carry out further attacks, especially since CoinMarketCap users have been subject to phishing campaigns in the past.
Other companies in the crypto industry, including Celsius, Ledger and BitMEX, have experienced similar leaks of email addresses and even users’ personal information. Each of these leaks occurred within the last 2 years.
In response to the data leak, CoinMarketCap reminded everyone of some basic rules of computer hygiene:
“We urge everyone to adopt good cybersecurity habits, and to have unique passwords on every site they use.”