Share this article

Popular Crypto Data Sites Targeted With Phishing Attack

Etherscan, CoinGecko and other sites displayed a suspicious pop-up asking users to connect their wallets.

Updated May 11, 2023, 5:31 p.m. Published May 13, 2022, 10:07 p.m. 1 min read
(wk1003mike/Shutterstock)

Crypto data websites Etherscan, CoinGecko and others reported incidents of a malicious pop-up prompting users to connect their MetaMask wallets.

The phishing attack appears to come from a domain displaying the Bored Ape Yacht Club logo. As of press time, the site tied to the domain appeared to be taken down. According to a WHOIS lookup, the domain was registered Friday around 3 p.m. ET.

"We are investigating the root cause of this attack to fix it as soon as possible," CoinGecko founder Bobby Ong told CoinDesk in a Telegram message.

“The situation is most likely caused by a malicious ad script by Coinzilla, a crypto ad network – we have disabled it now,” said Ong. “We are monitoring the situation further.”

In a tweet, Etherscan urged users to “not confirm any transactions” that popped up on its website.

CORRECTION (May 14, 14:49 UTC): DeFi Pulse was not one of the websites affected in the attack, as reported in an earlier version of this story.

More For You

Vitalik Buterin speaking at ETHDenver in February 2022

Privacy is widely seen as a necessary feature for the widespread adoption of blockchain technology. Ethereum is taking steps in that direction.

What to know:

  • Vitalik Buterin outlined three near-term Ethereum upgrades aimed at making privacy a native feature of the network rather than relying on third-party tools.
  • Account abstraction and FOCIL are designed to make private transactions harder to censor by changing how accounts work and how validators must include transactions in blocks.
  • Keyed...