Banksy Was Warned About Website Flaw Before NFT Hack Scam

Share post:

Professional US ethical hacker Sam Curry informed Banksy’s team that the artist’s website had a security flaw, seven days before a hacker defrauded a fan out of $336,000.

Curry, who is also the founder of security consulting firm Palisade, explained the earlier warnings: “I was in a security forum and multiple people were posting links to the site. I’d clicked one and immediately saw it was vulnerable, so I reached out to Banksy’s team via email as I wasn’t sure if anyone else had. They didn’t respond over email, so I tried a few other ways to contact them including their Instagram, but never received a response.”

While the new site, named “Banksy.co.uk/NFT”, was deleted soon after the auction, Curry informed that the site vulnerability “allowed you to create arbitrary files on the website” and publish your own pages and content.

The vulnerability has since been fixed, and the affected British NFT collector who was scammed reported that the hacker returned most of the money to him at the end of the day.

For more information, read the original story on the BBC.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Cyber Security Today, April 24, 2024 – Good news/bad news in Mandiant report, UnitedHealth admits paying a ransomware gang, and more

This episode reports on the danger of using expired open-source packages, a tool used by a Russian hacking group and passw

Google Play introduces new biometric verification with a user warning

Google has recently announced updates to the biometric verification process for Google Play purchases, aiming to bolster security...

Cyber Security Today, Week in Review for week ending Friday April 19, 2024

On this episode Jen Ellis, co-chair of the Ransomware Task Force, talks about ways of fighting one of the biggest cyber threats to IT d

Cyber Security Today, April 19, 2024 – Police bust phishing rental platform, a nine-year old virus found on Ukrainian computers, and more

This episode reports on a threat actor targeting governments in the Middle East with a novel way of hiding malware is going international

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways