🚨 Security Alert: CoinMarketCap Hit by Phishing Popup Breach! 🚨
On June 20, CoinMarketCap’s front end was compromised, exposing users to a fake “Verify Wallet” popup—here’s what happened and what you need to know:
🔹 Malicious popup urged users to connect their crypto wallets—a phishing attempt to steal funds
🔹 Breach exploited a backend API vulnerability linked to the site’s rotating “doodles” feature, injecting unauthorized JavaScript
🔹 Attack traced to a compromised third-party service, likely an ad network, highlighting supply chain risks
🔹 CoinMarketCap acted swiftly: popup removed, affected scripts disabled, and urgent warnings issued on X advising users NOT to connect wallets
🔹 No user funds reported stolen, but the incident underscores the importance of vigilance and strong security practices
🔹 Users advised to update passwords, enable 2FA, and never connect wallets to unexpected prompts
🔹 Incident raises awareness about the ongoing threat of phishing attacks and third-party vulnerabilities in crypto
Stay alert, always double-check wallet prompts, and prioritize your digital security! 💎🌐
https://cryptobriefing.com/coinmarketcap-security-breach-investigation/