HomeSecurityCoinMarketCap hacked: Site visitors' crypto stolen

CoinMarketCap hacked: Site visitors' crypto stolen

CoinMarketCap , one of the most popular cryptocurrency price monitoring platforms, was at the center of a website supply chain cyberattack , aimed at stealing the crypto of site visitors (via wallet drainer).

CoinMarketCap hacked: Site visitors' crypto stolen

The incident occurred on Friday night, when CoinMarketCap users began receiving suspicious Web3 pop-ups them to connect their crypto wallets to the site. Those who connected found that their wallets began to empty due to the activation of malicious code.

The company subsequently confirmed that cybercriminals exploited a vulnerability on the website's homepage, specifically through a "doodle" image, and introduced malicious JavaScript into the site.

See also: DOJ: Seizure of crypto linked to “pig butchering” scams

In an official announcement posted on X, CoinMarketCap stated: “On June 20, 2025, our security team identified a vulnerability related to a doodle image on our homepage. This doodle image contained a link that triggered malicious code via an API call, resulting in an unexpected pop-up window being displayed to some users when they visited our homepage,” reads a statement posted on X.

The company stressed that it reacted immediately, removing the malicious content, identifying the source of the problem and implementing additional security measures to prevent similar attacks in the future.

“We can confirm that all systems are now fully operational and that CoinMarketCap is safe for all users,” the announcement concludes.

According to an analysis by cybersecurity firm c/side, the attackers compromised CoinMarketCap’s API to retrieve a doodle image that was displayed on the homepage. The end result was the injection of a wallet drainer script into CoinMarketCap from an external domain called static.cdnkit[.]io.

When users visited the platform's homepage, a deceptive pop-up window appeared that mimicked a genuine connection request to the site. In reality, it was a wallet drainer, stealing victims' crypto assets.

See also: Predatory Sparrow “hit” Iranian Nobitex – Crypto theft

According to cybersecurity firm c/side, the attack did not occur directly on CoinMarketCap's servers, but on a third-party resource used by the platform — a typical example of a supply chain attack.

"These types of attacks are particularly difficult to detect, as they exploit trusted external elements embedded in the platform," c/side points out.

More details were later revealed by a known threat actor using the alias Rey, who said that the attackers shared a screenshot of the drainer panel on a Telegram channel. The screenshot revealed that $43,266 had already been stolen from at least 110 victims, and the Telegram channel appeared to host French-speaking attackers.

The CoinMarketCap case confirms a worrying trend: wallet drainers are becoming a key tool for cybercrime. Instead of traditional phishing methods, perpetrators are now promoting such attacks through social media, fake websites, malicious ads, and browser extensions that embed malicious exfiltration scripts.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

CoinMarketCap crypto wallet drainer theft

The statistics are revealing: in 2024 alone, it is estimated that more than $500 million was stolen through wallet drainer attacks, with perpetrators targeting over 300,000 wallets.

The escalation of these threats has already caused a backlash. Mozilla recently announced the integration of a new wallet drainer into browser add-ons uploaded to the Firefox Add-on repository.

The attack on CoinMarketCap is a very disturbing example of how vulnerable even large, popular sites remain to supply chain attacks. The fact that the breach occurred through a third-party source, rather than a direct server compromise, highlights one of the most insidious and difficult forms of cyberattack — because it relies on the trust a platform places on its partners or built-in services.

See also: The most common phishing scams for crypto users – How to recognize them

Using an innocent doodle on the homepage to inject malicious JavaScript is both clever and dangerous: it's a way that goes unnoticed by many security mechanisms and at the same time looks completely harmless to the end user. When the pop-up successfully imitates a legitimate Web3 transaction request, even experienced users can fall for the trap.

The incident is not just a “technical incident,” but a wake-up call for the entire Web3 ecosystem. It shows that user protection depends not only on the strength of infrastructure, but also on the constant monitoring of all the trust chains that make up a modern online experience. And for users, it is a reminder that “connect wallet” should always be treated with caution — even on familiar websites.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS