30,701 Blockchain Analyst Emails From the Dune Breach Just Surfaced on the Dark Web
HEROIC analysts identified a data breach linked to Dune, a Norway-based blockchain data analytics platform, on May 2, 2025. The incident exposed the email addresses of 30,701 registered users, extracted directly from a backend database and subsequently posted to an underground forum. While email addresses alone may not seem alarming at first, the audience here matters considerably. Dune is used primarily by crypto analysts, developers, and blockchain investors, making this a highly targeted and valuable list for anyone looking to run phishing campaigns or credential attacks against people with digital assets.
Why 30,701 Blockchain Analyst Emails Are Worth More Than They Appear
Email addresses tied to a blockchain analytics platform represent a concentrated list of people who are almost certainly involved with cryptocurrency in a professional or investment capacity. Attackers who acquire this list do not need passwords to cause harm. They can send convincingly crafted phishing messages that reference Dune's branding, fake alerts about a user's dashboards or wallet connections, or fraudulent invitations to click malicious links. Because the victims are technically sophisicated, attackers often elevate the quality of their lures to match, making deception harder to detect. The value of this list on a criminal marketplace is disproportionately high relative to its size.
What Was Exposed in the Dune Breach
- Email addresses for 30,701 registered Dune platform users
No passwords were included in this breach. The breach type was a direct database extraction, meaning the data came from Dune's own stored user records rather than from a third-party or partner system.
Why This Matters for Dune Users
Credential stuffing is an immediate concern: attackers will pair these email addresses with password lists from other breaches and attempt logins across crypto exchanges, wallets, and analytics tools. Account takeover of a Dune account itself could expose proprietary on-chain analysis, connected wallet data, or API keys tied to other services. Beyond direct account risks, identity theft and targeted financial fraud are real outcomes when verified email addresses from a crypto-focused platform circulate on dark web markets. The data does not expire, and it will continue to be used in attack campaigns long after the initial leak date.
How a Database Breach Happens on a Blockchain Analytics Platform
Despite the technical sophistication of companies operating in the blockchain space, database breaches remain a persistent threat. They occur when an attacker finds an unprotected endpoint, exploits a vulnerability in the web application, or gains access through compromised staff credentials. Once inside, they can extract user tables without triggering alarms, especially if security monitoring is not configured to detect unusual read activity on large tables. Dune's user email list appears to have been pulled from a production database in this manner, then surfaced on a forum known for trading stolen data sets. HEROIC's dark web monitoring systems detected the posting and traced it back to the Dune platform.
Check If Your Email Was Exposed in the Dune Breach
If you have ever registered for an account on Dune, your email address may be among the 30,701 records that were compromised in this breach. HEROIC offers a free breach scanner powered by a databse of over 400 billion exposed records, giving you instant insight into whether your information has appeared in this incident or any other known data leak. Running a check takes seconds and costs nothing. If your email is in the results, updating your passwords, enabling two-factor authentication, and being extra cautious of unsolicited messages are the right moves to make right away.
Breach Breakdown
30,701 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds