Cointelegraph Hit by Front-End Exploit, Fake Phishing Airdrop Pop Up on Website
Cointelegraph, a prominent cryptocurrency news outlet, experienced a significant security breach on Sunday. Attackers exploited a vulnerability in the website’s front-end, injecting malicious pop-up advertisements that mimicked legitimate cryptocurrency offerings. These deceptive ads falsely advertised “CoinTelegraph ICO Airdrops” and “CTG tokens,” promising users nearly $5,500 worth of tokens in exchange for connecting their crypto wallets.
The fraudulent pop-up included references to a “fair launch” event and a fabricated CertiK audit to enhance its credibility and deceive unsuspecting users. Cointelegraph swiftly responded to the incident, issuing a warning on X (formerly Twitter) urging readers to avoid clicking on the pop-ups, connecting their wallets, or providing any personal information. The company confirmed it was actively working to resolve the security issue and restore the website’s integrity.
This attack employed a common phishing technique where users are tricked into connecting their wallets under the guise of token claims, identity verification, or loyalty rewards. Once connected, attackers immediately drain the victim’s funds. The methodology is strikingly similar to a nearly identical exploit targeting CoinMarketCap two days prior. Both incidents involved embedding malicious code to display wallet phishing prompts, effectively transforming reputable news and data websites into unwitting tools for fraudulent activities.
The success of these attacks highlights the vulnerability of even established cryptocurrency platforms to sophisticated phishing techniques. By leveraging the trust users have in these well-known websites, attackers effectively bypassed typical user skepticism. This underscores the importance of heightened security measures and user vigilance in the cryptocurrency space. Users should remain cautious of unexpected pop-ups and prompts requesting wallet connections, particularly on seemingly trustworthy websites. Regular security updates and awareness of common phishing tactics are crucial for protecting personal funds and sensitive information within the cryptocurrency ecosystem. The incidents serve as a stark reminder of the ongoing need for robust cybersecurity practices within the industry.

