Etherscan, CoinGecko warn against ongoing MetaMask phishing attacks

Share This Post

While investigations are underway, the ongoing attack on various crypto platforms may be connected to the compromise of Coinzilla, an advertising and marketing agency.

Popular crypto analytics platforms Etherscan and CoinGecko have parallelly issued an alert against an ongoing phishing attack on their platforms. The firms began investigating the attack after numerous users reported unusual MetaMask pop-ups prompting users to connect their crypto wallets to the website. 

Based on the information disclosed by the analytics firms, the latest phishing attack attempts to gain access to users’ funds by requesting to integrate their crypto wallets via MetaMask once they access the official websites.

Etherscan further revealed that the attackers have managed to display phishing pop-ups via third-party integration and advised investors to refrain from confirming any transactions requested by MetaMask.

Pointing toward the possible cause of the attack, @Noedel19, a member of Crypto Twitter, connected the ongoing phishing attacks to the compromise of Coinzilla, an advertising and marketing agency, stating that “Any website that makes use of Coinzilla Ads are compromised.”

Compromised CoinZilla source code with phishing link. Source: @Noedel19

The screenshots shared below show the automated pop-up from MetaMask asking to connect with the link falsely portraying as Bored Ape Yacht Club’s (BAYC) non-fungible token (NFT) offering.

CoinGecko website showing fake MetaMask pop-up. Source: @Noedel19

On May 4, Cointelegraph further warned readers about the rise in Ape-themed airdrop phishing scams, which is further cemented by the latest warnings issued by Etherscan and CoinGecko.

While an official confirmation from Coinzilla is still underway, @Noedel19 suspects that all companies that have ad integration with Coinzilla remain at risk of similar attacks wherein their users get pop-ups for MetaMask integration.

As a primary means of damage control, Etherscan has disabled the compromised third-party integration on its website.

Coinzilla has not yet responded to Cointelegraph’s request for comment.

Related: Bored Ape Yacht Club NFTs stolen in Instagram phishing attack

The team behind BAYC recently warned investors about an attack after hackers were found to breach their official Instagram account.

As Cointelegraph reported on April 25, hackers were able to gain access to BAYC’s official Instagram account. The hackers then contacted BAYC’s Instagram followers and shared links to fake airdrops. 

Users who connected their MetaMask wallets to the scam website were subsequently drained of their Ape NFTs. Unconfirmed reports suggest that approximately 100 NFTs were stolen during the phishing attack.

Read Entire Article
spot_img

Related Posts

Republic First Bank Fails, Triggers Minor Crypto Market Downturn Amid Banking Sector Concerns

The United States witnessed its first banking failure of 2024 with the closure of Philadelphia-based Republic First Bank, creating ripples within the cryptocurrency community as Bitcoin, Ether, and

New UK Law Empowering Authorities to Seize and Destroy Crypto Assets Takes Effect Today

A new law enabling the National Crime Agency and police to seize, freeze, and destroy crypto assets is now in effect in the UK Under this law, police can seize crypto from suspects without needing to

New Data Reveals Bitcoin Mining May No Longer Be Profitable – Here’s Why

New data has revealed that Bitcoin (BTC) mining might no longer be as lucrative as it used to be Bloomberg has reported that the profitability of Bitcoin mining is nearing a record low, not seen

Forbes Unveils 20 Crypto ‘Zombies,’ Declares Ripple And XRP Among The Undead

In a controversial report, Forbes unveiled a list of 20 “crypto billion-dollar zombies,” Layer 1 (L1) tokens, which the news outlet defines as crypto assets with substantial valuations

Stablecoins Gain Ground as Global Financial Asset

According to Chainalysis’ “Crypto Spring Report,” stablecoin adoption and market importance are seeing a rapid increase in 2024, with a significant rise in the number of addresses holding them

Ethereum Sell Side Liquidity Thinning On CEXes: Time For $4,000?

Taking to X on April 26, one analyst notes that there is a high probability of Ethereum spiking in the sessions ahead because of thinning sell-side liquidity across major centralized exchanges like
- Advertisement -spot_img