I Found an Undocumented MCP Server on OpenSea — and It Leaked Usernames for Any Wallet
TL;DR: OpenSea runs an undocumented MCP server at mcp.opensea.io/mcp . One of its tools hands out API keys to anyone who asks, and another lets you resolve any Ethereum address with an OpenSea profile to its owner's username. Reported to Bugcrowd, now sharing the story and a free recon kit. The Setup I was poking around OpenSea's tooling one afternoon — just trying to understand how some of their…
A hidden server on OpenSea's website inadvertently exposed API keys, potentially allowing anyone to access usernames associated with any Ethereum wallet address. The discovery, documented by a security researcher, highlights the importance of securing undocumented internal APIs. Although OpenSea's internal tools properly required authentication for sensitive functions, the accidental exposure of API keys posed a significant privacy and security risk.
The researcher reported the vulnerability to OpenSea's Bugcrowd program, where it is currently being assessed. To help others understand the risks and how to mitigate them, the researcher has created a free PDF guide called the OpenSea MCP Server Recon Kit.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.