I Found an Undocumented MCP Server on OpenSea — and It Leaked Usernames for Any Wallet
A security researcher discovered an undocumented MCP server at mcp.opensea.io/mcp that exposed an unauthenticated tool, get_instant_api_key, allowing anyone to mint a valid OpenSea API key and then resolve Ethereum addre…