Breach Intelligence Report 13 May 2025

30,701 Blockchain Analyst Emails From the Dune Breach Just Surfaced on the Dark Web

HEROIC
HEROIC Threat Intelligence Team
Email Address
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 30,701
Source Type Database
Origin Darkweb
Password Type No Passwords

HEROIC analysts identified a data breach linked to Dune, a Norway-based blockchain data analytics platform, on May 2, 2025. The incident exposed the email addresses of 30,701 registered users, extracted directly from a backend database and subsequently posted to an underground forum. While email addresses alone may not seem alarming at first, the audience here matters considerably. Dune is used primarily by crypto analysts, developers, and blockchain investors, making this a highly targeted and valuable list for anyone looking to run phishing campaigns or credential attacks against people with digital assets.


Why 30,701 Blockchain Analyst Emails Are Worth More Than They Appear

Email addresses tied to a blockchain analytics platform represent a concentrated list of people who are almost certainly involved with cryptocurrency in a professional or investment capacity. Attackers who acquire this list do not need passwords to cause harm. They can send convincingly crafted phishing messages that reference Dune's branding, fake alerts about a user's dashboards or wallet connections, or fraudulent invitations to click malicious links. Because the victims are technically sophisicated, attackers often elevate the quality of their lures to match, making deception harder to detect. The value of this list on a criminal marketplace is disproportionately high relative to its size.


What Was Exposed in the Dune Breach

  • Email addresses for 30,701 registered Dune platform users

No passwords were included in this breach. The breach type was a direct database extraction, meaning the data came from Dune's own stored user records rather than from a third-party or partner system.


Why This Matters for Dune Users

Credential stuffing is an immediate concern: attackers will pair these email addresses with password lists from other breaches and attempt logins across crypto exchanges, wallets, and analytics tools. Account takeover of a Dune account itself could expose proprietary on-chain analysis, connected wallet data, or API keys tied to other services. Beyond direct account risks, identity theft and targeted financial fraud are real outcomes when verified email addresses from a crypto-focused platform circulate on dark web markets. The data does not expire, and it will continue to be used in attack campaigns long after the initial leak date.


How a Database Breach Happens on a Blockchain Analytics Platform

Despite the technical sophistication of companies operating in the blockchain space, database breaches remain a persistent threat. They occur when an attacker finds an unprotected endpoint, exploits a vulnerability in the web application, or gains access through compromised staff credentials. Once inside, they can extract user tables without triggering alarms, especially if security monitoring is not configured to detect unusual read activity on large tables. Dune's user email list appears to have been pulled from a production database in this manner, then surfaced on a forum known for trading stolen data sets. HEROIC's dark web monitoring systems detected the posting and traced it back to the Dune platform.


Check If Your Email Was Exposed in the Dune Breach

If you have ever registered for an account on Dune, your email address may be among the 30,701 records that were compromised in this breach. HEROIC offers a free breach scanner powered by a databse of over 400 billion exposed records, giving you instant insight into whether your information has appeared in this incident or any other known data leak. Running a check takes seconds and costs nothing. If your email is in the results, updating your passwords, enabling two-factor authentication, and being extra cautious of unsolicited messages are the right moves to make right away.

Breach Breakdown

Domain N/A
Leaked Data Email Address
Password Types No Passwords
Date Leaked 13 May 2025
Check in 5 seconds

30,701 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,134 scanned today
Breach Rank #9,147 by affected users
Impact Score
1
sensitivity + scale + recency
Est. Financial Impact $222.2K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance