Blog

Shuffle was hit by a data breach after third-party CRM hack


Shuffle, a leading crypto betting platform, suffered a data violation after the third-party customer service provider was compromised, revealing the data of most its users.

According to a Friday X Post From the founder of Shuffle NoA Dummett, the Customer Relations Management (CRM) service provider, the fast track, suffered a data violation that exposed its users’ data. Shuffle used the service discussed for “Programmatic Email Sending and various communications with users,” suggesting that messages and email addresses are likely to be among the exposed data.

“Unfortunately, it seems that their violation is affecting most of our users,” Dummett wrote. He said the company was investigating how the violation occurred and “where this data ended.”

The amount of data is likely to be significant. According to LikewebThe shuffle is the 12,064th most visited website in the world at the time of writing. Dummett also noted that the company is looking for successors to keep track of it quickly.

“We will also look for ways we can ease the dangers that exist in future 3rd party systems.”

Source: Noah Dummett

Neither the dummett or fast track responded to Cointelegraph’s request for comment through the time of publication.

Related: New York Crypto torture case is suspected of $ 1m bail each

Data violations affect the crypto industry

Although a data violation only exposes emails or customer support messages, crypto users face a higher risk because attacks can be armed with that information for phishing and social engineering-imperseonating exchange or wallets to steal private keys or funds. Unlike traditional accounts, cryptocurrency transactions are irreversible, meaning that a successful scam can result in a total and permanent loss.

A recent example is the database containing sensitive age -verification Data of more than 2.1 million users (including pictures of documents) leak from Discord, a gaming messaging platform popular with crypto users.

Last month, Crypto Exchange Declined Crypto.com declined that it maintains a 2023 data that leaks the details of the user details.

In the summer, Crypto ATM operator Bitcoin Depot notified its users with a data violation from mid-2024 Exposed private information of nearly 27,000 customers.

Coinbase was also reported to know in January that an employee of an outsourcing firm Customer data may leak.

Related: Bitcoin ‘Wrench attacks’ on track to double its worst year

Crypto data leaks put people in physical danger

Another issue derived from data leakage that could lead to the identity of crypto holders exposes them to the so-called $ 5 Wrench attack. This type of attack involves stealing a person’s cryptocurrency by physical threats or forcing them; The references in the name were struck by a wrench to display a person’s password, as described in an XKCD comics.

$ 5 Wrench attack comic. Source: Xkcd

By the end of August, an Indian anti-corruption court Sent 14 individuals to life imprisonment In a case involving crypto kidnapping and oppression from a trader based in the Surat in 2018. The situation has been a bad Warned of increasing $ 5 Wrench attacking And claimed that “every week, there is a Bitcoiner, at least one in the world, who is kidnapped, tortured, exposed, and sometimes worse.”

The situation worsens to the point where crypto carers experiences increasing interest in their services Due to the rising frequency of so-called “$ 5 wrench attacks” that target entrepreneurs, investors and project investors.

The shuffle incident features a repeated weakness throughout the cryptocurrency ecosystem – centralized mediators that hold the user’s sensitive data – and emphasizes the need for more transparent audit security and risk management skills.

Magazine: Here’s how to keep your crypto safe