• Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021
No Result
View All Result
CryptoABC.net
No Result
View All Result

CoinGecko Warn Users Of ‘Suspicious Pop Ups’ Phishing Attacks

May 17, 2022
in Australian Crypto News
Reading Time: 3min read
0 0
A A
0
CoinGecko Warn Users Of ‘Suspicious Pop Ups’ Phishing Attacks
0
SHARES
8
VIEWS
ShareShareShareShareShare

Several popular crypto websites, including those of data aggregator CoinGecko and Ethereum block explorer Etherscan, were targeted by a large-scale phishing scam last weekend that displayed malicious pop-ups prompting users to connect their MetaMask wallets.

Security Alert: If you are on the CoinGecko website and you are being prompted by your Metamask to connect to this site, this is a SCAM. Don’t connect it. We are investigating the root cause of this issue. pic.twitter.com/7vPfTAjtiU

— CoinGecko (@coingecko) May 13, 2022

The scam was linked to the now deactivated domain nftapes.win, which displayed the Bored Apes Yacht Club logo in an attempt to appear legitimate. At the time of writing, it was unclear how many users were affected and how much they lost.

🚨 We’ve received reports of phishing popups via a 3rd party integration and are currently investigating.

Please be careful not to confirm any transactions that pop up on the website.

— Etherscan (@etherscan) May 13, 2022

How the Scam Worked

According to CoinGecko, the scammers hijacked the advertising platform Coinzilla, which displays ads across a wide network of crypto-related sites, injecting malicious code that triggered the fraudulent pop-ups.

From there it was a relatively straightforward phishing scam leveraging the trust of the websites they exploited. The pop-ups would prompt users to connect their MetaMask wallets, and of course once they did their digital assets were immediately transferred to the scammers.

When the advertising code was identified as the root cause of the fraudulent pop-ups, it was deactivated on the CoinGecko website.

Advertising Code a Serious Vulnerability

Twitter user and blockchain researcher @CryptoShrine explained that this type of attack is quite common and suggests that Web3 site owners should look to move away from advertising as a primary source of revenue:

8/?

Ideally, the web3 related site owners should generate revenue through other means than just advertising

malvertising is a well-known tactic used by attackers in web2 space and can be extended to web3 space as well

— CryptoShine (@CryptoShine) May 14, 2022

Scams of this nature can cause significant losses because they can affect many websites at the same time by piggybacking on the advertising code, and because the malicious pop-ups can appear on trustworthy websites it increases the likelihood of users falling victim.

Similar Recent Phishing Scams

As crypto has gone more mainstream in the past 18 months, the number of phishing scams has dramatically increased. Last month alone saw MetaMask issue a security alert about a phishing scam affecting iCloud users and hardware wallet provider Trezor suffer a phishing scam that exploited its MailChimp newsletter.

Share this article

Join in the conversation on this article’s Twitter thread.

Disclaimer:
The content and views expressed in the articles are those of the original authors own and are not necessarily the views of Crypto News. We do actively check all our content for accuracy to help protect our readers. This article content and links to external third-parties is included for information and entertainment purposes. It is not financial advice. Please do your own research before participating.


Credit: Source link

ShareTweetSendPinShare
Previous Post

Lido Finance Warns Leveraged Traders As Staked ETH Loses Peg

Next Post

GoDaddy Website Hack Leaves DeFi Protocol ‘SpiritSwap’ Compromised

Next Post
GoDaddy Website Hack Leaves DeFi Protocol ‘SpiritSwap’ Compromised

GoDaddy Website Hack Leaves DeFi Protocol ‘SpiritSwap’ Compromised

You might also like

Ghana’s Crypto Push Begins As 11 Companies Enter SEC Sandbox

Ghana’s Crypto Push Begins As 11 Companies Enter SEC Sandbox

March 13, 2026
Ethereum Price Rejected Again, Market Watches Key Support Closely

Ethereum Price Rejected Again, Market Watches Key Support Closely

March 11, 2026
Nvidia Plans to add Innovation in the Metaverse with Software, Marketplace Deals

NVIDIA Megatron Core Gets Falcon-H1 Hybrid AI Architecture Support

March 9, 2026
Zcash Spinout ZODL Raises $25M After Electric Coin Company Exodus

Zcash Spinout ZODL Raises $25M After Electric Coin Company Exodus

March 10, 2026
Crypto Innovations and IBM’s Role in the Evolving Payments Landscape

IBM Releases Quantum-HPC Integration Blueprint Targeting Drug Discovery

March 12, 2026
Bitcoin Market Remains Pessimistic Despite Price Reclaiming $70k

Bitcoin Market Remains Pessimistic Despite Price Reclaiming $70k

March 14, 2026
CryptoABC.net

This is an Australian online news/education portal that aims to provide the latest crypto news, real-time updates, education and reviews within Australia and around the world. Feel free to get in touch with us!

What's New Here!

Ethereum Currently Undervalued – But Is It Time To Buy?

Ethereum Currently Undervalued – But Is It Time To Buy?

March 15, 2026
Crypto Leaders Push Back After Boris Johnson Calls Bitcoin a Ponzi

Crypto Leaders Push Back After Boris Johnson Calls Bitcoin a Ponzi

March 15, 2026

Subscribe Now

  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 cryptoabc.net - All rights reserved!

No Result
View All Result
  • Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021

© 2021 cryptoabc.net - All rights reserved!

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Please enter CoinGecko Free Api Key to get this plugin works.