Crypto
CoinMarketCap briefly hacked to drain crypto wallets via fake Web3 popup
CoinMarketCap, the popular cryptocurrency price tracking site, suffered a website supply chain attack that exposed site visitors to a wallet drainer campaign to steal visitors’ crypto.
On Friday evening, January 20, CoinMarketCap visitors began seeing Web3 popups asking them to connect their wallets to the site. However, when visitors connected their wallets, a malicious script drained cryptocurrency from them.
The company later confirmed threat actors utilized a vulnerability in the site’s homepage “doodle” image to inject malicious JavaScript into the site.
“On June 20, 2025, our security team identified a vulnerability related to a doodle image displayed on our homepage. This doodle image contained a link that triggered malicious code through an API call, resulting in an unexpected popup for some users when visited our homepage,” reads a statement posted on X.
“Upon discovery, We acted immediately to remove the problematic content, identified the root cause, and comprehensive measures have been implemented to isolate and mitigate the issue.”
“We can confirm all systems are now fully operational, and CoinMarketCap is safe and secure for all users.”
Cybersecurity firm c/side explained that the attack worked by the threat actors somehow modifying the API used by the site to retrieve a doodle image to display on the homepage. This tampered JSON payload now included a malicious script tag that injected a wallet drainer script into CoinMarketCap from an external site named “static.cdnkit[.]io”.
When someone visited the page, the script would execute and display a fake wallet connect popup showing CoinMarketCap branding and mimicking a legitimate Web3 transaction request. However, this script was actually a wallet drainer designed to steal connected wallets’ assets.
“This was a supply chain attack, meaning the breach didn’ target CMC’s own servers but a third-party tool or resource used by CMC,” explains c/side.
“Such attacks are hard to detect because they exploit trusted elements of a platform.”
More details about the attack came later from a threat actor known as Rey, who said that the attackers behind the CoinMarketCap supply chain attack shared a screenshot of the drainer panel on a Telegram channel.
This panel indicated that $43,266 was stolen from 110 victims as part of this supply chain attack, with the threat actors speaking in French on the Telegram channel.
Source: Rey
As the popularity of cryptocurrency has boomed, so has the threat from wallet drainers, which are commonly used in attacks.
Unlike traditional phishing, these types of attacks are more often promoted through social media posts, advertisements, spoofed sites, and malicious browser extensions that include malicious wallet-draining scripts.
Reports indicate that wallet drainers stole almost $500 million in 2024 through attacks targeting more than 300,000 wallet addresses.
The problem has become so pervasive that Mozilla recently introduced a new system to detect wallet drainers in browser add-ons uploaded to the Firefox Add-on repository.
Patching used to mean complex scripts, long hours, and endless fire drills. Not anymore.
In this new guide, Tines breaks down how modern IT orgs are leveling up with automation. Patch faster, reduce overhead, and focus on strategic work — no complex scripts required.
Crypto
Institutional Crypto Adoption ‘Happening Now’: Ripple Executive Says Real-World Use Cases Taking Hold
Key Takeaways:
- Ripple says institutional adoption of digital assets is happening now.
- Craddock states the focus has shifted to infrastructure and real-world use cases.
- Paris events showed strong momentum, with Ripple citing real industry energy.
Institutional Digital Asset Adoption Gains Momentum
Institutional adoption of digital assets is gaining momentum across global finance, marking a decisive shift as major firms move beyond experimentation into active deployment. Ripple’s managing director for the U.K. and Europe, Cassie Craddock, reinforced this momentum on April 20, pointing to Paris Blockchain Week 2026 and related industry events as evidence that large-scale crypto adoption is already underway.
Craddock stated on social media platform X:
“Institutional adoption of digital assets isn’t something that’s on the horizon. It’s happening now.”
“The debate has moved on. The focus is on infrastructure and real-world use cases. And the people I was fortunate enough to spend time with this week are the ones building it. Banks, asset managers, fintechs, and regulators, all discussing how to do this properly and at scale,” she further shared.
The executive tied that view to meetings held across the Ripple Roadshow Paris, Paris Blockchain Week itself, Mastercard Crypto Day at the Eiffel Tower, and Société Générale-FORGE’s event at the French Ministry of Finance. She explained that discussions no longer centered on whether institutions would engage with the sector. Instead, participants examined infrastructure, deployment standards, and real-world use cases that could support broader activity across regulated financial markets.
Paris Events Highlight Structured Industry Buildout
The comments suggest that digital asset conversations among large organizations are becoming more operational. Craddock referenced exchanges with speakers including David Durouchoux, Myles Harrison, and Frédéric Dalibard, while also highlighting the presence of banks, asset managers, fintechs, and regulators. That mix suggests several parts of the financial system are considering similar questions around scale and execution. Rather than focusing on abstract potential, the gatherings in Paris appeared to center on how institutions can build and apply digital asset systems in a structured way.
The Ripple executive added that the people involved in those meetings are “the ones building it.” She also concluded:
“The energy was real, the momentum even more so.”
These remarks reflect Ripple’s view that institutional interest is moving from long-term expectation to active development. By stressing implementation and participation from established financial groups, the post framed Paris Blockchain Week as a signal that digital asset adoption is advancing within mainstream finance.
Crypto
Scattered Spider hacker pleads guilty to stealing $8 million in cryptocurrency – Help Net Security
A British national tied to the Scattered Spider cybercrime group pleaded guilty to hacking multiple companies via SMS phishing and stealing over $8 million in virtual currency from US victims.
Tyler Robert Buchanan, 24, of Dundee, Scotland, pleaded guilty to conspiracy to commit wire fraud and aggravated identity theft.
In November 2024, US authorities unsealed criminal charges against Buchanan and four other alleged members of the Scattered Spider group, accusing them of using phishing text messages to steal employee credentials, breach company systems and steal cryptocurrency.
According to court documents, Buchanan and his co-conspirators conducted cyber intrusions and virtual currency thefts between September 2021 and April 2023.
The victims included interactive entertainment, telecommunications and technology companies, as well as business process outsourcing (BPO) and IT service providers, cloud communications firms, virtual currency companies and individual victims.
“As part of the scheme, Buchanan and his co-conspirators conducted Short Message Service (SMS) phishing attacks by sending hundreds of SMS phishing messages to the mobile telephones of a victim company’s employees. The messages purported to be from the victim company or a contracted IT or BPO supplier for the victim company,” the Justice Department said.
“The SMS phishing messages contained links to phishing websites designed to look like legitimate websites of a victim company or a contracted IT or BPO supplier. The websites then lured the recipient into providing confidential information, including personal identifying information (PII), and account usernames and passwords.”
In April 2023, police found on a digital device at Buchanan’s residence in Scotland the names and addresses of numerous victims, including a text file containing cryptocurrency seed phrases and login credentials for one account.
Buchanan has been in federal custody since April 2025 and faces up to 22 years in federal prison.
Co-conspirator Noah Michael Urban is serving a 10-year federal prison sentence and was ordered to pay $13 million in restitution after pleading guilty in April 2025 to fraud-related charges. Three other defendants charged alongside Buchanan, including Ahmed Hossam Eldin Elbadawy, Evans Onyeaka Osiebo and Joel Martin Evans, still face criminal charges in the case.
Scattered Spider is a cybercrime collective, also known as UNC3944, Muddled Libra and Octo Tempest, made up largely of young, native English-speaking hackers who use social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass MFA, and compromise enterprise networks.
The group gained notoriety for its role in high-profile hacking and extortion attacks against Caesars Entertainment and MGM Resorts International, two of the largest casino operators in the US.
Although authorities have increased pressure on the group and arrested several members, including four they consider responsible for ransomware attacks targeting UK-based retailers last year, the group continues to operate, with new members replacing those arrested.
Crypto
XRP Prepares for Quantum Future as Ripple Maps XRPL Strategy for Security Readiness
Key Takeaways:
- Ripple outlines a phased roadmap to prepare XRPL for quantum-era cryptography risks.
- Industry momentum grows as XRPL testing highlights performance and security tradeoffs.
- Developers at Ripple will expand testing to balance innovation with network stability.
Ripple Maps Quantum Security Strategy
Ripple’s post-quantum strategy reflects a growing shift in blockchain security as quantum computing risks gain credibility. The company’s latest Insight, published April 20 by Senior Director of Engineering Ayo Akinyele, outlined a structured roadmap to prepare the XRP Ledger for future cryptographic disruption while preserving network performance.
The Insight stated:
“Ripple is introducing a multi-phase roadmap to prepare the XRP Ledger (XRPL) for a post-quantum future, with a target for full readiness by 2028.”
It also detailed collaboration efforts: “Ripple is working with Project Eleven to accelerate development, including validator testing and early custody prototypes.”
Akinyele explained that quantum security is becoming more relevant because blockchain networks rely on cryptographic systems that could eventually be broken by sufficiently advanced quantum computers. On XRPL, each signed transaction reveals a public key on-chain, which could weaken long-term wallet security in a post-quantum environment.
He also pointed to the “harvest now, decrypt later” threat, where attackers collect cryptographic data today and wait for future quantum capabilities to exploit it. While this does not indicate an immediate failure of current protections, it increases the urgency of preparing systems that secure long-duration value. These risks reinforce the need for early testing of quantum-resistant cryptographic systems and structured migration planning.
XRPL Testing Targets Long-Term Stability
Ripple’s roadmap consists of four phases, starting with contingency planning for a potential failure of existing cryptographic standards. This includes a “Quantum-Day” framework designed to enable secure migration to post-quantum accounts if vulnerabilities emerge. Additional phases focus on evaluating National Institute of Standards and Technology (NIST)-recommended algorithms under real network conditions, measuring impacts on throughput, storage, and verification efficiency. XRPL’s native features, including key rotation and deterministic key generation, provide a technical advantage by enabling gradual migration without forcing users to abandon existing accounts. Parallel testing on development networks will allow developers to assess performance tradeoffs before broader implementation.
The senior director of engineering emphasized long-term execution and coordination, stating:
“We should not view addressing the quantum threat on XRPL as a single upgrade, but rather a multi-phased strategy of carefully migrating a live, global financial infrastructure without compromising the value of digital assets protected by the XRPL.”
Akinyele indicated that achieving post-quantum readiness requires balancing cryptographic innovation with operational stability, ensuring the network remains efficient while adapting to future security challenges.
-
Lifestyle6 minutes agoWhat are Angelenos giving away in one Buy Nothing group? All this treasured stuff
-
Politics12 minutes agoCommentary: He honked to support a ‘No Kings’ rally. A cop busted him
-
Sports24 minutes agoSun Valley Poly High’s Fabian Bravo shows flashes of Koufax dominance
-
World36 minutes agoMoldovan oligarch sentenced to 19 years in prison over $1bn fraud
-
New York3 hours agoTrump’s Immigration Crackdown Pervades Long Island Suburbs
-
Detroit, MI3 hours agoChris Simms projects Detroit Lions first-round NFL draft pick
-
San Francisco, CA3 hours agoSan Francisco sets $3.4B price tag for public takeover of PG&E
-
Dallas, TX3 hours agoGame Day Guide: Stars at Wild | Dallas Stars