Share this article

Popular Crypto Data Sites Targeted With Phishing Attack

Etherscan, CoinGecko and other sites displayed a suspicious pop-up asking users to connect their wallets.

(wk1003mike/Shutterstock)
(wk1003mike/Shutterstock)

Crypto data websites Etherscan, CoinGecko and others reported incidents of a malicious pop-up prompting users to connect their MetaMask wallets.

The phishing attack appears to come from a domain displaying the Bored Ape Yacht Club logo. As of press time, the site tied to the domain appeared to be taken down. According to a WHOIS lookup, the domain was registered Friday around 3 p.m. ET.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

"We are investigating the root cause of this attack to fix it as soon as possible," CoinGecko founder Bobby Ong told CoinDesk in a Telegram message.

“The situation is most likely caused by a malicious ad script by Coinzilla, a crypto ad network – we have disabled it now,” said Ong. “We are monitoring the situation further.”

In a tweet, Etherscan urged users to “not confirm any transactions” that popped up on its website.

CORRECTION (May 14, 14:49 UTC): DeFi Pulse was not one of the websites affected in the attack, as reported in an earlier version of this story.

Tracy Wang

Tracy Wang was the deputy managing editor of CoinDesk's finance and deals team, based in New York City. She has reported on a wide range of topics in crypto, including decentralized finance, venture capital, exchanges and market-makers, DAOs and NFTs. Previously, she worked in traditional finance ("tradfi") as a hedge funds analyst at an asset management firm. She owns BTC, ETH, MINA, ENS, and some NFTs. Tracy won the 2022 George Polk award in Financial Reporting for coverage that led to the collapse of cryptocurrency exchange FTX. She holds a B.A. in Economics from Yale College.

Tracy Wang