A prominent cryptocurrency news website, Cointelegraph, recently fell victim to a sophisticated front-end hack. Malicious pop-ups promoting a fake token airdrop appeared on the site, tricking users into connecting their crypto wallets and potentially draining their assets. This incident follows a similar attack on CoinMarketCap, highlighting a growing trend of phishing scams targeting crypto platforms.
Cointelegraph Website Compromised
On Sunday night, Cointelegraph confirmed that its website had been compromised, leading to the display of fraudulent pop-ups. The company promptly issued a warning to its users via social media, advising them not to interact with the pop-ups, connect their wallets, or input any personal information. The attack aimed to deceive visitors into believing they were eligible for a giveaway of a new token, falsely claiming it was part of a "fair launch initiative" by Cointelegraph to reward loyal readers.
The Deceptive Airdrop Scam
The malicious pop-up presented a fabricated token price and promised users a substantial amount of tokens, approximately $5,500 worth, if they connected their cryptocurrency wallets. It even falsely claimed that the smart contract had been audited by the security firm CertiK to lend an air of legitimacy. The scam's objective was to lure users into connecting their wallets under false pretenses, subsequently allowing attackers to drain their accounts.
Key Takeaways
-
Cointelegraph's website experienced a front-end hack, displaying fraudulent pop-ups.
-
The pop-ups promoted a fake token airdrop, enticing users with promises of significant returns.
-
Users were urged not to click on the pop-ups, connect their wallets, or enter personal information.
-
The attack mirrors a recent exploit on CoinMarketCap, indicating a pattern of phishing attempts.
-
Blockchain security firm Scam Sniffer identified the threat, suggesting the malicious code originated from Cointelegraph's advertising system.
Similarities to Previous Attacks
This incident bears a striking resemblance to a front-end attack that occurred just two days prior on CoinMarketCap, another major cryptocurrency price aggregator. In that case, visitors encountered pop-ups requesting wallet connections for verification. CoinMarketCap later confirmed that malicious code had been injected into its site. Both incidents underscore a concerning rise in phishing attacks that target crypto platforms by compromising user interfaces.
The Broader Threat Landscape
According to TRM Labs, a blockchain intelligence firm, phishing schemes and malware-based infrastructure attacks accounted for 70% of the $2.2 billion stolen in crypto-related hacks in 2024. The Cointelegraph attack also comes shortly after security researchers revealed a massive data dump containing over 16 billion stolen login credentials, potentially assembled from infostealer malware, credential stuffing, and prior data breaches. These events highlight the persistent and evolving threats faced by the cryptocurrency community.
Sources
-
Cointelegraph Website Hacked in Fake Airdrop Phishing Attack, Decrypt.
-
CoinTelegraph Allegedly Hacked as Fake Crypto Airdrop Scam Targets Users, Cyber Kendra.
This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.