Banksy Was Warned About Website Flaw Before NFT Hack Scam

Share post:

Professional US ethical hacker Sam Curry informed Banksy’s team that the artist’s website had a security flaw, seven days before a hacker defrauded a fan out of $336,000.

Curry, who is also the founder of security consulting firm Palisade, explained the earlier warnings: “I was in a security forum and multiple people were posting links to the site. I’d clicked one and immediately saw it was vulnerable, so I reached out to Banksy’s team via email as I wasn’t sure if anyone else had. They didn’t respond over email, so I tried a few other ways to contact them including their Instagram, but never received a response.”

While the new site, named “Banksy.co.uk/NFT”, was deleted soon after the auction, Curry informed that the site vulnerability “allowed you to create arbitrary files on the website” and publish your own pages and content.

The vulnerability has since been fixed, and the affected British NFT collector who was scammed reported that the hacker returned most of the money to him at the end of the day.

For more information, read the original story on the BBC.

SUBSCRIBE NOW

Related articles

Security research team claims to have helped avert a major supply chain attack

JFrog Security Research team continuously scans public repositories such as Docker Hub, NPM, and PyPI to identify malicious...

Phishing attacks on state and local governments surge by 360%

Phishing attacks targeting state and local governments have surged by 360% between May 2023 and May 2024, according...

What is Ticketmaster saying to its customers?

Here's the letter that has been sent out out to Ticketmaster clients that a reader sent to me....

Cyber Security Today, July 8, 2024 – New ransomware group discovered, and summer podcast break starts

A new ransomware group is discovered. Welcome to Cyber Security Today. It's Monday July 8th, 2024. I'm Howard Solomon,...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways