Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » CoinMarketCap Hit by Supply Chain Attack, Wallets Drained

CoinMarketCap Hit by Supply Chain Attack, Wallets Drained

Malicious script exploited homepage vulnerability to target crypto users

Kelly Cromley by Kelly Cromley
Jun 23, 2025
in Market News, News
Reading Time: 3 mins read
0
CoinMarketCap

CoinMarketCap, a leading platform for tracking cryptocurrency prices, recently experienced a significant cybersecurity breach involving a supply chain attack that compromised the safety of its website visitors. The incident exposed users to a wallet drainer campaign, resulting in stolen cryptocurrency from unsuspecting individuals who interacted with a malicious popup.

The issue began surfacing on the evening of June 20, 2025, when users visiting CoinMarketCap encountered unexpected Web3 prompts requesting wallet connections. While these popups appeared to be legitimate, they were actually part of a coordinated attack involving injected malicious scripts. Once users connected their wallets through the popup interface, their assets were covertly transferred to the attackers.

According to an official statement released by CoinMarketCap, the breach was traced to a vulnerability linked to the homepage’s animated doodle image. The company explained that the image contained a link which triggered unauthorized JavaScript code via an API call. This led to the popup appearing for some users upon visiting the homepage.

CoinMarketCap confirmed that its security team acted promptly upon discovering the issue. The malicious content was removed, the source of the problem identified, and a series of remediation measures were introduced to prevent future exploitation. The platform assured users that normal operations had resumed and that its systems were fully secure once again.

CoinMarketCap is hacked… you will get drained!pic.twitter.com/cwSFQ0M0rg

— Dark Web Informer – Cyber Threat Intelligence (@DarkWebInformer) June 20, 2025


Messages in "com"-related group chats revealed that a threat actor using the moniker "Spadle" is behind the CMC attack.

😉 pic.twitter.com/egWp1tBmfB

— Rey (@ReyXBF) June 21, 2025


Cybersecurity researchers at c/side later provided further technical insights into the breach. They stated that the attack was carried out by altering the JSON payload of the API responsible for displaying the doodle image. The altered data included a script tag that introduced a wallet-draining script sourced from an external domain named “static.cdnkit[.]io.” This script generated a convincing wallet connection popup using CoinMarketCap’s branding, tricking users into authorizing transactions that ultimately drained their crypto wallets.

On June 20, 2025, our security team identified a vulnerability related to a doodle image displayed on our homepage. This doodle image contained a link that triggered malicious code through an API call, resulting in an unexpected pop-up for some users when visited our homepage.…

— CoinMarketCap (@CoinMarketCap) June 21, 2025


🚨 Be aware of scammers!

🔹 CoinMarketCap will NEVER DM you first. If you receive a message claiming to be from CMC & asking for funds, it's a scam!

Always verify before sending out your funds!

Stay #SAFU

— CoinMarketCap (@CoinMarketCap) June 22, 2025


Analysts classified the breach as a supply chain attack, where the compromise occurred not on CoinMarketCap’s servers directly, but through a third-party service integrated into the platform. These types of attacks are notably difficult to detect because they exploit elements perceived as trusted within a system’s architecture.

Additional details about the breach emerged from a threat actor operating under the alias Rey. According to cybersecurity sources, the attacker disclosed information via a Telegram group, where they also shared a screenshot of the drainer panel. This dashboard indicated that approximately $43,266 worth of cryptocurrency was stolen from 110 victims during the incident. The attackers were reportedly communicating in French within the Telegram channel.

This breach highlights the rising threat of wallet drainers across the cryptocurrency ecosystem. Unlike traditional phishing scams, wallet-draining attacks are increasingly disseminated through social media, fake advertisements, spoofed websites, and browser extensions embedded with malicious scripts.

Recent data indicates that wallet drainer attacks were responsible for nearly $500 million in stolen assets throughout 2024, impacting over 300,000 wallet addresses. In response to the growing problem, platforms like Mozilla have begun deploying detection systems in their browser repositories to identify and block harmful wallet-draining extensions.

The CoinMarketCap incident underscores the urgency for platforms operating in the Web3 space to implement stronger safeguards against sophisticated attack vectors, particularly those involving third-party integrations. As decentralized technologies continue to expand, so too does the need for vigilant, multi-layered cybersecurity protocols.

Previous Post

Kazakhstan Unveils Solana Economic Zone for Web3 Growth

Next Post

PwC and Web3 Harbour outline five enablers to drive decentralized finance

Related Posts

1money

1Money Unveils Stablecoin Platform Ahead of New Payment Chain

by Kelly Cromley
Dec 5, 2025
0

1Money, a company led by former Binance.US chief executive Brian Shroder, has announced the rollout of a new stablecoin orchestration...

coz partners with iron studios

COZ and Iron Studios Unveil Web3 Collectibles at CCXP25

by Kelly Cromley
Dec 5, 2025
0

A new collaboration between COZ and Brazil-based collectible maker Iron Studios is set to introduce blockchain-enabled ownership to traditional pop...

The Open Network (TON)

Telegram’s Cocoon Aims to Redefine Private, Decentralized AI

by Kelly Cromley
Dec 5, 2025
0

Telegram has introduced Cocoon, a decentralized AI computation network built on the TON blockchain, marking a significant move toward privacy-preserving...

base

Base–Solana Bridge Targets Smoother Crosschain Liquidity

by Kelly Cromley
Dec 5, 2025
0

Base has introduced a Chainlink-secured bridge connecting its Ethereum layer-2 network with the Solana blockchain, marking a notable step toward...

bullfrog power

Bullfrog Power Launches Blockchain Tokens to Boost Sustainability Trust

by Kelly Cromley
Dec 5, 2025
0

Bullfrog Power has introduced a new initiative aimed at strengthening transparency in environmental reporting by issuing tokenized sustainability certificates on...

titan trading platform

Titan–Zeni Alliance Aims to Elevate AI-Powered Crypto Trading

by Kelly Cromley
Dec 5, 2025
0

Titan Trading Platform has revealed a strategic collaboration with Zeni.io, a provider specializing in data infrastructure tailored for AI agents....

Next Post
Web3 Harbour

PwC and Web3 Harbour outline five enablers to drive decentralized finance

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

1money
Market News

1Money Unveils Stablecoin Platform Ahead of New Payment Chain

by Kelly Cromley
Dec 5, 2025
coz partners with iron studios
Market News

COZ and Iron Studios Unveil Web3 Collectibles at CCXP25

by Kelly Cromley
Dec 5, 2025
The Open Network (TON)
Market News

Telegram’s Cocoon Aims to Redefine Private, Decentralized AI

by Kelly Cromley
Dec 5, 2025
base
Market News

Base–Solana Bridge Targets Smoother Crosschain Liquidity

by Kelly Cromley
Dec 5, 2025
bullfrog power
Market News

Bullfrog Power Launches Blockchain Tokens to Boost Sustainability Trust

by Kelly Cromley
Dec 5, 2025

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.