Dark Web Intel: 9,846 Earnscape Crypto Accounts Exposed in Database Breach
Threat intelligence sourced from dark web forums confirms a database breach at Earnscape, an Icelandic cryptocurrency-rewards platform, with data surfacing in September 2024. The exposure covers 9,846 user records and includes personally identifiable information that can be weaponized for targeted phishing and account takeover operations across interconnected crypto services. No passwords were included in this breach, but the combination of contact details and financial platform affiliation makes affected users a high-value target for social engineering.
Why This Is Dangerous
Cryptocurrency platform users are among the most targeted individuals in the threat landscape. Even without passwords, a confirmed list of verified crypto-platform email addresses and phone numbers gives attackers everything they need to launch SIM-swapping campaigns, spear-phishing emails, and SMS-based fraud. When attackers know which platform a person uses, they can craft convincing impersonation messages designed to steal login credentials or seed phrases.
What Was Exposed
- Email Address -- direct channel for phishing and account recovery attacks
- Phone Number -- enables SIM-swap attempts and SMS phishing
- Username -- aids in cross-platform account correlation and credential guessing
Why This Matters
Even a breach without passwords carries serious downstream risk:
- Credential stuffing: Attackers pair this email list with passwords from other breaches to attempt logins at Earnscape and elsewhere.
- Account takeover: Phone numbers enable SIM swapping, bypassing two-factor authentication entirely.
- Identity theft: Combined contact details allow attackers to impersonate financial service providers convincingly.
- Targeted fraud: Knowing a person holds crypto assets makes them a high-value mark for investment scams and fake support requests.
How Database Breaches Work
A database breach typically occurs when an attacker exploits a vulnerability in a web application, an exposed server, or weak access controls to gain direct access to a company's backend database. The attacker extracts user records in bulk and the data is later sold or published on dark web marketplaces. Unlike phishing, which targets one user at a time, a single database breach can expose tens of thousands of accounts in seconds. Platforms in emerging sectors like cryptocurrency often move fast and may not have mature security controls in place when they first launch.
Check If You Are Affected
Heroic's Have I Been Pwned tool searches across 400+ billion breached records, including data from this Earnscape breach. Enter your email address to find out immediately whether your information was exposed -- and what other breaches may have captured your data over time.
Breach Breakdown
9,846 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds