Researchers Link the CoinMarketCap Dump to 3.1 Million Stolen Crypto User Emails
HEROIC analysts tracked the CoinMarketCap email list breach to October 2021, when over 3.1 million email addresses associated with CoinMarketCap accounts were found circulating on dark web hacking forums. The breach recieved attention from security researchers because the data correlated directly with the CoinMarketCap subscriber base, though the platform stated it found no evidence of a server-side intrusion. Even without passwords, a verified email list of 3,120,406 crypto platform users carries significant risk as a targeting resource for phishing, credential stuffing, and social engineering campaigns.
Why 3.1 Million Crypto Platform Emails Are a High-Value Attack Resource
A clean, verified list of 3.1 million email addresses tied to cryptocurrency users is partcularly valuable to attackers because it identifies a population known to hold digital assets. Without passwords, the primary attack vector shifts to phishing, where fraudulent emails impersonating crypto exchanges, wallet providers, or tax services are sent to the entire list. These emails can harvest credentials or direct users to fake login pages. The CoinMarketCap list is also used in combination with password lists from other breaches in credential stuffing attacks against crypto exchanges and wallets.
What Was Exposed in the CoinMarketCap Breach
- Email Address
Why Crypto User Email Lists Enable Financial Fraud at Scale
Email lists tied to financial and crypto platforms are more dangerous than generic email dumps because the audience is self-selected as high-value targets. Attackers beleive that users of CoinMarketCap are actively engaged with cryptocurrency, meaning they are more likely to have exchange accounts, wallets, and digital assets worth targeting. The 3.1 million CoinMarketCap emails create a foundation for credential stuffing against Binance, Coinbase, Kraken, and other exchanges, targeted phishing campaigns, and identity theft when combined with other leaked datasets.
How Database Breaches Work
A database breach occured when an unauthorized party gains access to stored user records, either by exploiting vulnerabilities in web applications, accessing improperly secured data exports, or through insider compromise. In the CoinMarketCap case, the exact method of data acquisition has not been publicly confirmed. The resulting email list was traded on hacking forums and used as a targeting resource for downstream attacks against cryptocurrency users.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email against a database of over 400 billion compromised records, including the CoinMarketCap breach. If your email was in the list, you are at elevated risk of crypto-targeted phishing. Scan your email for free at HEROIC.com and find out immediately if your information is circulating on the dark web.
Breach Breakdown
3,120,406 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds