Data leak
"Popular Crypto Data Sites Targeted With Phishing Attack"
Primary Source ↗Incident Details
Popular cryptocurrency websites including Etherscan, CoinGecko, and DeFi Pulse were showing users a pop-up prompting them to connect their MetaMask wallets. CoinGecko founder Bobby Ong stated that he believed the culprit was a malicious advertising script from a crypto ad network called Coinzilla. The advertisement appeared to be from a site mimicking the popular Bored Apes Yacht Club NFT project, which was taken down after the scam was discovered. It’s as yet unclear how many users accepted the prompt, or what malicious actions (if any) were taken.
Technical Details
- Initial Attack Vector
- Smart contract exploit / hack
- Vendor / Product
- Phishing attack via Etherscan and CoinGecko
Timeline
- 2022-05-13 Breach occurred
- 2022-05-13 Publicly disclosed