CoinMarketCap Briefly Exploited With Wallet Phishing Pop-Up Message
Hackers infiltrated CoinMarketCap's front-end system through a seemingly innocuous doodle image, injecting malicious code that triggered fake wallet verification pop-ups. The breach Leveraged the platform's backend API to deliver a manipulated JSON payload, embedding JavaScript into the homepage. Blockchain security firm Coinspect Security confirmed the attack vector.
The script displayed an unauthorized "Verify Wallet" prompt, a classic phishing tactic designed to steal crypto holdings. Attackers exploited the platform's rotating "doodles" feature, bypassing core infrastructure changes. CoinMarketCap swiftly removed the pop-up after detection, stating, "Comprehensive measures have been implemented to isolate and mitigate the issue."
No user impact disclosures were made regarding potential wallet compromises. The incident highlights persistent security vulnerabilities in crypto data platforms despite their market dominance.