By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
CapitalatorCapitalator
Notification Show More
Latest News
UK electricity networks under fire for pushing advice costs on to customers
May 27, 2022
The Lex Newsletter: we should all be (Groucho) Marxists in investment and politics
May 27, 2022
Whirlwind talks led to Broadcom’s $69.1bn capture of VMware
May 27, 2022
G7 urges Opec to raise output to cool oil market
May 27, 2022
Vanessa Nakate: Africa needs climate grants, not loans
May 27, 2022
Aa
  • NewsLive
  • Business
  • Politics
  • Investing
  • Finance
  • Companies
  • Markets
  • Crypto
  • Careers
  • Climate
  • Life
  • Tech
  • Videos
Reading: Etherscan, CoinGecko warn against ongoing MetaMask phishing attacks
Share
CapitalatorCapitalator
Aa
  • News
  • Business
  • Politics
  • Markets
  • Crypto
  • Companies
  • Finance
  • Investing
  • Careers
  • Climate
  • Lifestyle
  • Tech
  • Videos
Search
  • Categories
  • Bookmarks
    • Customize Interests
    • My Bookmarks
  • More Foxiz
    • Blog Index
    • Sitemap
Have an existing account? Sign In
Follow US
Capitalator > Crypto > Etherscan, CoinGecko warn against ongoing MetaMask phishing attacks
Crypto

Etherscan, CoinGecko warn against ongoing MetaMask phishing attacks

Alexander Müller
Alexander Müller May 14, 2022
Updated 2022/05/14 at 6:11 AM
Share
SHARE

Popular crypto analytics platforms Etherscan and CoinGecko have parallelly issued an alert against an ongoing phishing attack on their platforms. The firms began investigating the attack after numerous users reported unusual MetaMask pop-ups prompting users to connect their crypto wallets to the website. 

Based on the information disclosed by the analytics firms, the latest phishing attack attempts to gain access to users’ funds by requesting to integrate their crypto wallets via MetaMask once they access the official websites.

Security Alert: If you are on the CoinGecko website and you are being prompted by your Metamask to connect to this site, this is a SCAM. Don’t connect it. We are investigating the root cause of this issue. pic.twitter.com/7vPfTAjtiU

— CoinGecko (@coingecko) May 13, 2022

Etherscan further revealed that the attackers have managed to display phishing pop-ups via third-party integration and advised investors to refrain from confirming any transactions requested by MetaMask.

We’ve received reports of phishing popups via a 3rd party integration and are currently investigating.

Please be careful not to confirm any transactions that pop up on the website.

— “The Etherscan” (@etherscan) May 13, 2022

Pointing toward the possible cause of the attack, @Noedel19, a member of Crypto Twitter, connected the ongoing phishing attacks to the compromise of Coinzilla, an advertising and marketing agency, stating that “Any website that makes use of Coinzilla Ads are compromised.”

Compromised CoinZilla source code with phishing link. Source: @Noedel19

The screenshots shared below show the automated pop-up from MetaMask asking to connect with the link falsely portraying as Bored Ape Yacht Club’s (BAYC) non-fungible token (NFT) offering.

CoinGecko website showing fake MetaMask pop-up. Source: @Noedel19

On May 4, Cointelegraph further warned readers about the rise in Ape-themed airdrop phishing scams, which is further cemented by the latest warnings issued by Etherscan and CoinGecko.

While an official confirmation from Coinzilla is still underway, @Noedel19 suspects that all companies that have ad integration with Coinzilla remain at risk of similar attacks wherein their users get pop-ups for MetaMask integration.

As a primary means of damage control, Etherscan has disabled the compromised third-party integration on its website.

Coinzilla has not yet responded to Cointelegraph’s request for comment.

Related: Bored Ape Yacht Club NFTs stolen in Instagram phishing attack

The team behind BAYC recently warned investors about an attack after hackers were found to breach their official Instagram account.

There is no mint going on today. It looks like BAYC Instagram was hacked. Do not mint anything, click links, or link your wallet to anything.

— Bored Ape Yacht Club (@BoredApeYC) April 25, 2022

As Cointelegraph reported on April 25, hackers were able to gain access to BAYC’s official Instagram account. The hackers then contacted BAYC’s Instagram followers and shared links to fake airdrops. 

Users who connected their MetaMask wallets to the scam website were subsequently drained of their Ape NFTs. Unconfirmed reports suggest that approximately 100 NFTs were stolen during the phishing attack.

Alexander Müller May 14, 2022
Share this Article
Facebook TwitterEmail Print
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

You Might Also Like

Crypto

Two key takeaways from Nansen’s UST stablecoin depeg report

May 27, 2022
Crypto

Hacker tastes own medicine as community gets back stolen NFTs

May 27, 2022
Crypto

Draft bill to ban China’s digital yuan from US app stores

May 27, 2022
Crypto

Terra to burn 1B UST from the community pool as holders vote for it

May 27, 2022

Capitalator

  • Business
  • Careers
  • Climate
  • Crypto
  • Finance
  • Investing
  • Markets
  • Technology

© 2022 Capitalator. All Rights Reserved.

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?