Etherscan, CoinGecko warn against ongoing MetaMask phishing attacks

Popular crypto analytics platforms Etherscan and CoinGecko have parallelly issued an alert against an ongoing phishing attack on their platforms. The firms began investigating the attack after numerous users reported unusual MetaMask pop-ups prompting users to connect their crypto wallets to the website. 

Based on the information disclosed by the analytics firms, the latest phishing attack attempts to gain access to users’ funds by requesting to integrate their crypto wallets via MetaMask once they access the official websites.

Etherscan further revealed that the attackers have managed to display phishing pop-ups via third-party integration and advised investors to refrain from confirming any transactions requested by MetaMask.

Pointing toward the possible cause of the attack, @Noedel19, a member of Crypto Twitter, connected the ongoing phishing attacks to the compromise of Coinzilla, an advertising and marketing agency, stating that “Any website that makes use of Coinzilla Ads are compromised.”

Compromised CoinZilla source code with phishing link. Source: @Noedel19

The screenshots shared below show the automated pop-up from MetaMask asking to connect with the link falsely portraying as Bored Ape Yacht Club’s (BAYC) non-fungible token (NFT) offering.

CoinGecko website showing fake MetaMask pop-up. Source: @Noedel19

On May 4, Cointelegraph further warned readers about the rise in Ape-themed airdrop phishing scams, which is further cemented by the latest warnings issued by Etherscan and CoinGecko.

While an official confirmation from Coinzilla is still underway, @Noedel19 suspects that all companies that have ad integration with Coinzilla remain at risk of similar attacks wherein their users get pop-ups for MetaMask integration.

As a primary means of damage control, Etherscan has disabled the compromised third-party integration on its website.

Coinzilla has not yet responded to Cointelegraph’s request for comment.

Related: Bored Ape Yacht Club NFTs stolen in Instagram phishing attack

The team behind BAYC recently warned investors about an attack after hackers were found to breach their official Instagram account.

As Cointelegraph reported on April 25, hackers were able to gain access to BAYC’s official Instagram account. The hackers then contacted BAYC’s Instagram followers and shared links to fake airdrops. 

Users who connected their MetaMask wallets to the scam website were subsequently drained of their Ape NFTs. Unconfirmed reports suggest that approximately 100 NFTs were stolen during the phishing attack.

All Dutch and English crypto news!

Traders look beyond Cardano (ADA) and Shiba Inu (SHIB), outclassed by the RECQ presale

TLDR Some traders have been opting for the Rebel Satoshi Arcade presale ahead of Cardano and Shiba Inu. As a new altcoin, it boasts significant upside potential...

Miners could shift to AI after Bitcoin halving; Expert believes Borroe Finance ($ROE) could be positioned for next wave of growth

TLDR: CoinShares stated in a report that Bitcoin miners Could gravitate towards the AI sector to bolster revenue after BTC halving. Borroe Finance ($ROE) is an AI-funding...

Ethereum ETF gelist door Franklink Templeton, maar goedkeuring SEC lijkt ver weg

Franklin Templeton, een grote speler in vermogensbeheer, heeft een nieuw product gelanceerd: de Franklin Ethereum TR Ethereum ETF, afgekort EZET. Deze ETF, die direct gekoppeld is...

Analyse: kan Shiba Inu 90% stijgen vanuit dit punt?

Shiba Inu is de afgelopen week bezig geweest met een daling, maar daardoor gebeurt er wel iets positiefs. De munt lijkt zich weer af te...

Beste exchanges

Koop je crypto bij Bitvavo