Nansen, an Ethereum blockchain analytics, has allegedly suffered a data breach attack on one of its third-party vendors. This affected entity is an analytics providing solution on Ethereum wallet activity, emerging projects, and investment decisions.
Reports claimed the breach happened on one of the company’s authentication providers earlier this week. Moreover, Nansen has immediately rolled out notifications amongst its users to maintain their transparency and security.
An unknown attacker allegedly conducted the breach by acquiring access to an admin panel controlling customer access to the Nansen analytics platform. Fortunately, the platform has quickly addressed the situation by deploying its mitigation protocol. They prevented the malicious activity upon receiving an alert from its vendor.
The Nansen data breach could still impact several users despite the prevention.
Nansen disclosed that approximately 6.8% of its users could suffer from the data breach incident since the attackers could have acquired their email addresses. The attack has also compromised a smaller subset of password hashes.
Additionally, the attackers might have scanned a very minute cluster of blockchain addresses. The platform’s support team has reached out to these affected users. They suggested that these users should reset their passwords to prevent further exploitation.
This cryptocurrency firm also warned these users that they were at risk of phishing attempts since the hackers harvested details about their digital asset ownership and email addresses. Naturally, the attack has raised concerns about the security of users’ cryptocurrency holdings.
There is a possibility that the scope of the impact may expand to include more users as investigations into the breach are still ongoing. As a precautionary measure, Nansen advised all its users, even those without a notification, to reset their passwords. These proactive actions aim to ensure the safety and security of the entire Nansen community.
This newly discovered breach against Nansen shows that even the most trusted entities can fall victim to these attacks. Fortunately, this crypto platform has executed proactive measures, swift responses, and user awareness.
However, users should still be careful with unsolicited communications since the threat actors could use what they acquired during their attack to execute other malicious attacks.