HomeSecurityBreach exposes 35,000 Ethereum addresses to crypto draining attack

Breach exposes 35,000 Ethereum addresses to crypto draining attack

A malicious actor compromised the Ethereum mailing list provider and sent a phishing email to more than 35,000 addresses with a link to a malicious website running a crypto draining program .

See also: Ethereum: Abused to steal $60 million from 99,000 victims

Ethereum crypto drain

Ethereum revealed the incident in a blog post this week and said it had no material impact on users.

Attack details

The attack occurred on the evening of June 23rd when an email was sent from the address “updates@blog.ethereum.org” to 35,794 addresses.

Ethereum says the malicious actor used a combination of its own list of email addresses and an additional 3,759 that were extracted from the platform’s blog mailing list. However, only 81 of the extracted addresses were previously unknown to the attacker.

The message lured recipients to the malicious crypto draining website, announcing a partnership with Lido DAO and inviting them to take advantage of the 6.8% annual percentage yield (APY) on staked Ethereum. By clicking on the embedded “Start Staking” button to receive the promised returns on investment, users were taken to a fake but professionally crafted website created to appear as part of the promotion.

See also: FBI: New crypto scams – Cybercriminals impersonate lawyers

If users connected wallets to this website and signed the requested transaction, a crypto draining device would empty their wallets, sending all funds to the attacker.

Breach exposes 35,000 Ethereum addresses to crypto draining attack

Ethereum says its internal security team launched an investigation as soon as possible to identify the attacker, understand the purpose of the attack, determine the timeline, and identify affected parties.

The attacker was quickly blocked from sending more phishing emails, and Ethereum took to Twitter to alert the community to the malicious emails, warning everyone not to click on the link. Ethereum also submitted the malicious link to various blocklists, which led to it being blocked by most Web3 wallet providers and Cloudflare.

On-chain transaction analysis showed that none of the email recipients fell for the scam during the campaign. Ethereum concludes by saying that it has taken additional measures and is moving some email services to other providers to prevent a repeat of such an incident.

See also: Hackers target HFS servers to install cryptominers

Crypto draining, as in the case of Ethereum addresses, refers to the unauthorized transfer of cryptocurrency from a user’s wallet without their consent. This malicious activity can occur for a variety of reasons, including phishing scams, malware attacks, and the exploitation of vulnerabilities in blockchain or crypto wallet software. Once cryptocurrency is drained, it is often difficult to track down and recover due to the anonymous nature of blockchain transactions. To protect against crypto draining, users are advised to employ strong security measures, such as using hardware wallets, enabling two-factor authentication, and being vigilant against phishing attempts.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS