No Result
View All Result
  • Login
Friday, October 31, 2025
FeeOnlyNews.com
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
No Result
View All Result
FeeOnlyNews.com
No Result
View All Result
Home Cryptocurrency

CoinMarketCap’s front-end compromised, investigation underway

by FeeOnlyNews.com
4 months ago
in Cryptocurrency
Reading Time: 3 mins read
A A
0
CoinMarketCap’s front-end compromised, investigation underway
Share on FacebookShare on TwitterShare on LInkedIn


Key Takeaways

CoinMarketCap’s front end was compromised, displaying unauthorized wallet verification pop-ups to users.
The breach exploited a backend API vulnerability linked to the platform’s doodles feature, prompting an ongoing investigation.

Share this article

CoinMarketCap’s front end was compromised on June 20, with its webpage displaying unauthorized pop-up messages asking visitors to verify their crypto wallets. The malicious pop-up was first flagged by several crypto community members.

The platform’s team confirmed the incident and warned users against connecting their wallets while they investigate and work to resolve the issue.

🚨 Security Alert

We’re aware that a malicious pop-up prompting users to “Verify Wallet” has appeared on our site.

⚠️ Do NOT connect your wallet.

Our team is actively investigating and working to resolve the issue.

— CoinMarketCap (@CoinMarketCap) June 20, 2025

Blockchain security service provider Coinspect Security has uncovered that CoinMarketCap’s backend API is delivering manipulated JSON payloads designed to inject malicious JavaScript through its rotating “doodles” feature.

🚨 CoinMarketCap’s backend API serves manipulated JSON data that injects malicious JavaScript through the rotating “doodles” feature. Not all users see it, since the doodle shown varies per visit. The injected wallet drainer always loads if you visit /doodles/ pic.twitter.com/13o9aB7JlW

— Coinspect Security (@coinspect) June 20, 2025

Yes, CoinMarketCap drainer loaded from a “doodle” JSON file. Lottie is a JSON-based animation file format that enables designers to easily ship animations on any platform. We are investigating this injection vector and other web sites and dApps must consider it. https://t.co/hac2PdFe48

— Coinspect Security (@coinspect) June 20, 2025

Also today, Crypto Briefing noticed signs of a similar security incident on another popular crypto website.

The webpage displayed a pop-up claiming an “exclusive airdrop” opportunity, which was distinct from the CoinMarketCap incident but similarly prompted visitors to connect their wallets through claiming the airdrop.

Crypto Briefing was unable to confirm whether the site’s front-end was compromised, given that the suspicious behavior appeared to last only around five minutes. The site quickly returned to normal, and the pop-up was no longer visible.

The breach follows a cybersecurity report from Cybernews revealing 16 billion exposed passwords in one of the largest data breaches in history, affecting access to major platforms including Facebook, Google, and Apple.

Experts recommend that users update passwords for all major accounts, especially those connected to sensitive services such as work platforms. Users are strongly advised to use a password manager to generate strong, unique passwords for each account.

Extra security measures, including enabling two-factor authentication (2FA) and closely monitoring accounts, should also be considered.

Share this article

Follow on Google News





Source link

Tags: CoinMarketCapscompromisedfrontendinvestigationunderway
ShareTweetShare
Previous Post

Trump says Iran has ‘maximum’ two weeks to avoid US air strikes, dismisses Europe peace efforts

Next Post

Crypto & NFT Data Tracker CoinMarketCap Got Hacked

Related Posts

Decentralized Crypto Exchange Plans Year-End Debut, Reuters

Decentralized Crypto Exchange Plans Year-End Debut, Reuters

by FeeOnlyNews.com
October 31, 2025
0

dYdX (DYDX), one of the leading decentralized cryptocurrency trading platforms in the industry, is reportedly preparing to enter the US...

Binance Supercharges Crypto Adoption in Argentina With a QR Code Bridge to the Peso

Binance Supercharges Crypto Adoption in Argentina With a QR Code Bridge to the Peso

by FeeOnlyNews.com
October 31, 2025
0

Binance is supercharging crypto’s real-world momentum with a groundbreaking push into Argentina’s digital payments scene, launching instant, fee-free QR crypto...

Strategy Q3 Income Narrows to .8B as mNAV Shrinks

Strategy Q3 Income Narrows to $2.8B as mNAV Shrinks

by FeeOnlyNews.com
October 30, 2025
0

Shares in Strategy have risen nearly 6% after hours as the Bitcoin treasury company reported a net income of $2.8...

Canary Funds updates S-1 filing for XRP spot ETF, targeting November 13 launch

Canary Funds updates S-1 filing for XRP spot ETF, targeting November 13 launch

by FeeOnlyNews.com
October 30, 2025
0

Key Takeaways Canary Funds updated its S-1 for an XRP spot ETF, removing the delaying amendment. The ETF could launch...

Ripple Depends On XRP Price, Not Market Utility: Experts

Ripple Depends On XRP Price, Not Market Utility: Experts

by FeeOnlyNews.com
October 30, 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure The long-running dispute over what XRP is...

.7 Trillion T. Rowe Price Files for First U.S. Spot Shiba Inu ETF, Boosting SHIB’s Adoption

$1.7 Trillion T. Rowe Price Files for First U.S. Spot Shiba Inu ETF, Boosting SHIB’s Adoption

by FeeOnlyNews.com
October 30, 2025
0

T. Rowe Price has officially filed for the Shiba Inu ETF with the U.S. SEC. If approved, this could be...

Next Post
Crypto & NFT Data Tracker CoinMarketCap Got Hacked

Crypto & NFT Data Tracker CoinMarketCap Got Hacked

0K–0K Range Shows Rising Short Interest

$100K–$110K Range Shows Rising Short Interest

  • Trending
  • Comments
  • Latest
AB Infrabuild, among 5 cos to approach record date for stock splits. Last day to buy for eligibility

AB Infrabuild, among 5 cos to approach record date for stock splits. Last day to buy for eligibility

October 15, 2025
Housing Market Loses Steam, “National Buyer’s Market” Likely in 2026

Housing Market Loses Steam, “National Buyer’s Market” Likely in 2026

October 14, 2025
Are You Losing Out Because of Medicare Open Enrollment Mistakes?

Are You Losing Out Because of Medicare Open Enrollment Mistakes?

October 13, 2025
Coinbase boosts investment in India’s CoinDCX, valuing exchange at .45B

Coinbase boosts investment in India’s CoinDCX, valuing exchange at $2.45B

October 15, 2025
Government shutdown could drain financial advisor optimism

Government shutdown could drain financial advisor optimism

October 7, 2025
Getting Started: How to Register

Getting Started: How to Register

October 10, 2025
ECB October 2025 rate decision

ECB October 2025 rate decision

0
Decentralized Crypto Exchange Plans Year-End Debut, Reuters

Decentralized Crypto Exchange Plans Year-End Debut, Reuters

0
Breast cancer drug stock Olema could more than double from here, analysts say

Breast cancer drug stock Olema could more than double from here, analysts say

0
Trump-Putin summit canceled after Moscow sends memo to Washington – FT (SPY:NYSEARCA)

Trump-Putin summit canceled after Moscow sends memo to Washington – FT (SPY:NYSEARCA)

0
High Dividend 50: Timbercreek Financial Corp.

High Dividend 50: Timbercreek Financial Corp.

0
15 Best Bank Promotions & Bonus Offers for October 2025

15 Best Bank Promotions & Bonus Offers for October 2025

0
Decentralized Crypto Exchange Plans Year-End Debut, Reuters

Decentralized Crypto Exchange Plans Year-End Debut, Reuters

October 31, 2025
Trump-Putin summit canceled after Moscow sends memo to Washington – FT (SPY:NYSEARCA)

Trump-Putin summit canceled after Moscow sends memo to Washington – FT (SPY:NYSEARCA)

October 31, 2025
Getting Started: Inventory Types and Conditions

Getting Started: Inventory Types and Conditions

October 31, 2025
Binance Supercharges Crypto Adoption in Argentina With a QR Code Bridge to the Peso

Binance Supercharges Crypto Adoption in Argentina With a QR Code Bridge to the Peso

October 31, 2025
Strategy Q3 Income Narrows to .8B as mNAV Shrinks

Strategy Q3 Income Narrows to $2.8B as mNAV Shrinks

October 30, 2025
El Pollo Loco outlines plan for nearly doubling 2026 unit growth amid margin gains and menu innovation (NASDAQ:LOCO)

El Pollo Loco outlines plan for nearly doubling 2026 unit growth amid margin gains and menu innovation (NASDAQ:LOCO)

October 30, 2025
FeeOnlyNews.com

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Economy
  • Financial Planning
  • Investing
  • Market Analysis
  • Markets
  • Money
  • Personal Finance
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Decentralized Crypto Exchange Plans Year-End Debut, Reuters
  • Trump-Putin summit canceled after Moscow sends memo to Washington – FT (SPY:NYSEARCA)
  • Getting Started: Inventory Types and Conditions
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclaimers
  • About Us
  • Contact Us

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.