Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » CoinMarketCap Hit by Supply Chain Attack, Wallets Drained

CoinMarketCap Hit by Supply Chain Attack, Wallets Drained

Malicious script exploited homepage vulnerability to target crypto users

Kelly Cromley by Kelly Cromley
Jun 23, 2025
in Market News, News
Reading Time: 3 mins read
0
CoinMarketCap

CoinMarketCap, a leading platform for tracking cryptocurrency prices, recently experienced a significant cybersecurity breach involving a supply chain attack that compromised the safety of its website visitors. The incident exposed users to a wallet drainer campaign, resulting in stolen cryptocurrency from unsuspecting individuals who interacted with a malicious popup.

The issue began surfacing on the evening of June 20, 2025, when users visiting CoinMarketCap encountered unexpected Web3 prompts requesting wallet connections. While these popups appeared to be legitimate, they were actually part of a coordinated attack involving injected malicious scripts. Once users connected their wallets through the popup interface, their assets were covertly transferred to the attackers.

According to an official statement released by CoinMarketCap, the breach was traced to a vulnerability linked to the homepage’s animated doodle image. The company explained that the image contained a link which triggered unauthorized JavaScript code via an API call. This led to the popup appearing for some users upon visiting the homepage.

CoinMarketCap confirmed that its security team acted promptly upon discovering the issue. The malicious content was removed, the source of the problem identified, and a series of remediation measures were introduced to prevent future exploitation. The platform assured users that normal operations had resumed and that its systems were fully secure once again.

CoinMarketCap is hacked… you will get drained!pic.twitter.com/cwSFQ0M0rg

— Dark Web Informer – Cyber Threat Intelligence (@DarkWebInformer) June 20, 2025


Messages in "com"-related group chats revealed that a threat actor using the moniker "Spadle" is behind the CMC attack.

😉 pic.twitter.com/egWp1tBmfB

— Rey (@ReyXBF) June 21, 2025


Cybersecurity researchers at c/side later provided further technical insights into the breach. They stated that the attack was carried out by altering the JSON payload of the API responsible for displaying the doodle image. The altered data included a script tag that introduced a wallet-draining script sourced from an external domain named “static.cdnkit[.]io.” This script generated a convincing wallet connection popup using CoinMarketCap’s branding, tricking users into authorizing transactions that ultimately drained their crypto wallets.

On June 20, 2025, our security team identified a vulnerability related to a doodle image displayed on our homepage. This doodle image contained a link that triggered malicious code through an API call, resulting in an unexpected pop-up for some users when visited our homepage.…

— CoinMarketCap (@CoinMarketCap) June 21, 2025


🚨 Be aware of scammers!

🔹 CoinMarketCap will NEVER DM you first. If you receive a message claiming to be from CMC & asking for funds, it's a scam!

Always verify before sending out your funds!

Stay #SAFU

— CoinMarketCap (@CoinMarketCap) June 22, 2025


Analysts classified the breach as a supply chain attack, where the compromise occurred not on CoinMarketCap’s servers directly, but through a third-party service integrated into the platform. These types of attacks are notably difficult to detect because they exploit elements perceived as trusted within a system’s architecture.

Additional details about the breach emerged from a threat actor operating under the alias Rey. According to cybersecurity sources, the attacker disclosed information via a Telegram group, where they also shared a screenshot of the drainer panel. This dashboard indicated that approximately $43,266 worth of cryptocurrency was stolen from 110 victims during the incident. The attackers were reportedly communicating in French within the Telegram channel.

This breach highlights the rising threat of wallet drainers across the cryptocurrency ecosystem. Unlike traditional phishing scams, wallet-draining attacks are increasingly disseminated through social media, fake advertisements, spoofed websites, and browser extensions embedded with malicious scripts.

Recent data indicates that wallet drainer attacks were responsible for nearly $500 million in stolen assets throughout 2024, impacting over 300,000 wallet addresses. In response to the growing problem, platforms like Mozilla have begun deploying detection systems in their browser repositories to identify and block harmful wallet-draining extensions.

The CoinMarketCap incident underscores the urgency for platforms operating in the Web3 space to implement stronger safeguards against sophisticated attack vectors, particularly those involving third-party integrations. As decentralized technologies continue to expand, so too does the need for vigilant, multi-layered cybersecurity protocols.

Previous Post

Kazakhstan Unveils Solana Economic Zone for Web3 Growth

Next Post

PwC and Web3 Harbour outline five enablers to drive decentralized finance

Related Posts

core dao

Core Foundation Unveils Rev+ to Reward Token Activity

by Kelly Cromley
Jul 16, 2025
0

The Core Foundation has introduced Rev+, a protocol-level initiative designed to share blockchain revenue with developers and stablecoin issuers based...

Tac

Tac Blockchain Bridges Telegram Mini Apps to Ethereum

by Kelly Cromley
Jul 16, 2025
0

Tac, a newly introduced Layer 1 blockchain compatible with the Ethereum Virtual Machine (EVM), has officially launched its mainnet with...

invincible read

Blockchain Meets Books in Invincible Read’s Web3 Push

by Kelly Cromley
Jul 16, 2025
0

Invincible Read has unveiled its next-generation educational platform designed around Web3 technologies, aiming to transform traditional reading into an engaging,...

MoonPay supports Revolut Pay

MoonPay Adds Revolut Pay for One-Click Crypto Purchases

by Kelly Cromley
Jul 15, 2025
0

MoonPay has expanded its fiat on-ramp capabilities by integrating Revolut Pay, allowing users to buy cryptocurrencies with a single click...

Standard Chartered Executes Trade Financing Deal Using Blockchain

Standard Chartered Launches Institutional Crypto Trading Service

by Kelly Cromley
Jul 15, 2025
0

Standard Chartered has introduced a secure, fully integrated digital asset trading service specifically designed for institutional clients. This move is...

zoro partners with pai3 ai

Zoro and PAI3 Unite to Build Ethical, Verifiable AI Agents

by Kelly Cromley
Jul 15, 2025
0

ZoRobotics (ZORO), a decentralized AI network for machine learning, has announced a strategic partnership with PAI3 AI, a decentralized platform...

Next Post
Web3 Harbour

PwC and Web3 Harbour outline five enablers to drive decentralized finance

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • Central Bank of Saudi Arabia Teams Up with Ripple to Transform Cross-Border Settlements

    by Kelly Cromley
    Aug 17, 2023
  • GameStop’s Digital Transformation: Embracing Blockchain and NFTs

    by Kelly Cromley
    Feb 2, 2025

Recent News

core dao
Market News

Core Foundation Unveils Rev+ to Reward Token Activity

by Kelly Cromley
Jul 16, 2025
Tac
Market News

Tac Blockchain Bridges Telegram Mini Apps to Ethereum

by Kelly Cromley
Jul 16, 2025
invincible read
Market News

Blockchain Meets Books in Invincible Read’s Web3 Push

by Kelly Cromley
Jul 16, 2025
MoonPay supports Revolut Pay
Market News

MoonPay Adds Revolut Pay for One-Click Crypto Purchases

by Kelly Cromley
Jul 15, 2025
Standard Chartered Executes Trade Financing Deal Using Blockchain
Market News

Standard Chartered Launches Institutional Crypto Trading Service

by Kelly Cromley
Jul 15, 2025

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.
I Agree