Security reminder!

Users of OpenSea are at risk because an employee of their email vendor, Customer.io, misused their access to Customer.io’s systems to download and share email addresses with an unauthorised third party. Impacted email addresses include those provided by OpenSea users and subscribers to their newsletter.

Please be extra cautious about email safety during this time. For reference, below are some email safety best practices. 

 Safety Recommendations:

  1. Be cautious of phishing emails from addresses trying to impersonate OpenSea. OpenSea will ONLY send you emails from the domain: ‘opensea.io.’ Please do not engage with any email claiming to be from OpenSea that does not come from this email domain. 
  2. Never download anything from an OpenSea email. Authentic OpenSea emails do not include attachments or requests to download anything.
  3. Check the URL of any page linked in an OpenSea email. They will only include hyperlinks to ‘email.opensea.io’ URLs. Make sure that ‘opensea.io’ is spelled correctly, as it’s common for malicious actors to impersonate URLs by shuffling letters.
  4. Never share or confirm your passwords or secret wallet phrases. OpenSea will never prompt you to do this – in any format.
  5. Never sign a wallet transaction prompted directly from an email. OpenSea emails will never contain links that directly prompt you to sign a wallet transaction. Never sign a wallet transaction that doesn’t list the origin of https://opensea.io if you were led there by email.

Relevant resources: