tradingkey.logo
tradingkey.logo
Search

Cointelegraph Joins The Victim List—Who’s Behind The Crypto Hacks?

BitcoinistJun 23, 2025 9:00 PM
facebooktwitterlinkedin
View all comments(0)

Visitors to Cointelegraph were caught off guard on Sunday when a slick pop-up claimed they’d won 50,000 “CTG” tokens worth over $5,000.

The message looked real, complete with Cointelegraph branding and familiar airdrop elements. Many users were prompted to connect their crypto wallets before the scam was revealed.

By the time the fake offer disappeared, unsuspecting visitors had already clicked through, risking their funds.

Fake Airdrop Interface

According to Scam Sniffer, the bogus pop-up included a countdown timer and buttons that felt just like a standard token drop. It even showed a reward worth $5,490 and labeled the process “secure,” “instant,” and “verified.”

Based on reports, none of those descriptions were true. There is no CTG token on CoinGecko, CoinMarketCap, or any major blockchain explorer. That should have been a red flag.

Attack Via Ad System

Security experts traced the malicious JavaScript back to Cointelegraph’s ad partner rather than its core website code.

Cointelegraph later confirmed that the breach came through its advertising system and not a flaw in its main infrastructure.

A similar hack hit CoinMarketCap over the same weekend, showing that attackers are now focusing on trusted ad networks to slip in harmful scripts.

Wallet Draining Threat

Once a user clicked “connect,” the hidden code could trigger wallet approvals and transfers without clear consent.

Effectively, hackers have blanket permission to transfer money out of a wallet in seconds. This approach is riskier than standard phishing emails because they sneak up on individuals unexpectedly on sites they trust.

Calls For Improved Defenses

As these ad-based attacks become increasingly prevalent, crypto platforms come under pressure to lock down all third-party integrations.

Experts recommend more rigorous audits of ad code, sandboxing of third-party scripts, and real-time monitoring of site activity. On the end-user side, installing ad blockers or script-blocking add-ons would preclude these stealth threats.

Based on what transpired this weekend, it’s apparent that attackers have changed their modus operandi from email cons to front-end hacks on prominent sites. Cointelegraph and CoinMarketCap are only the latest victims.

Featured image from Unsplash, chart from TradingView

Disclaimer: The information provided on this website is for educational and informational purposes only and should not be considered financial or investment advice.

Comments (0)

Click the $ button, enter the symbol, and select to link a stock, ETF, or other ticker.

0/500
Commenting Guidelines
Loading...

Recommended Articles

tradingkey.logo
Risk Warning: Our Website and Mobile App provides only general information on certain investment products. Finsights does not provide, and the provision of such information must not be construed as Finsights providing, financial advice or recommendation for any investment product.
Investment products are subject to significant investment risks, including the possible loss of the principal amount invested and may not be suitable for everyone. Past performance of investment products is not indicative of their future performance.
Finsights may allow third party advertisers or affiliates to place or deliver advertisements on our Website or Mobile App or any part thereof and may be compensated by them based on your interaction with the advertisements.
© Copyright: FINSIGHTS MEDIA PTE. LTD. All Rights Reserved.