CoinMarketCap Hacked, Scrambles to Remove Malicious Wallet Verification Popup
CoinMarketCap was hacked on Friday after a malicious popup appeared on its website, urging users to “verify” their wallets. Key Takeaways: CoinMarketCap was hacked after a fake wallet verification popup appeared on its s...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
CoinMarketCap was hacked on Friday after a malicious popup appeared on its website, urging users to “verify” their wallets.
Key Takeaways:
- CoinMarketCap was hacked after a fake wallet verification popup appeared on its site, triggering phishing concerns.
- MetaMask and Phantom flagged the site as unsafe, warning users against connecting wallets.
- The breach has revived criticism of CoinMarketCap’s security, nearly four years after its major data leak.
The phishing-style notification asked users to connect their wallets and approve ERC-20 token access, raising immediate red flags across the crypto community.
Wallet providers like MetaMask and Phantom quickly flagged the site as unsafe, with Phantom displaying a browser warning against using the platform.
CoinMarketCap Removes Malicious PopupIn a Friday post on X, CoinMarketCap confirmed the removal of the malicious popup. “We’ve identified and removed the malicious code from our site,” the platform said.
The company added that it is continuing to investigate the breach and is reinforcing its security measures to prevent similar incidents.
Update: We've identified and removed the malicious code from our site.
Our team is continuing to investigate and taking steps to strengthen our security.
The malicious prompt, which triggered warnings from wallet providers like MetaMask and Phantom, reportedly asked users to connect their wallets and approve access to ERC-20 tokens.
Phantom’s browser extension even flagged CoinMarketCap as “unsafe to use,” raising concerns about the platform’s vulnerability.
Reports of the phishing attempt began circulating across crypto social media, with several users alerting others not to interact with the prompt.
Many suspected the attack was an attempt to steal wallet credentials through a fake interface mimicking a legitimate verification process.
The incident has reignited concerns about CoinMarketCap’s security, coming nearly four years after a 2021 data breach exposed the email addresses of over 3.1 million users.
That data was later discovered for sale on hacking forums, prompting criticism over the platform’s safeguards.
SECURITY ALERT
We're seeing reports that @CoinMarketCap's front end has been compromised and is trying to trick people into linking their wallets, presumably to drain them. pic.twitter.com/a0JREDSPvS
CoinMarketCap, owned by Binance, remains one of the most widely used resources in the crypto space, making it a prime target for malicious actors looking to exploit its credibility.
Users are urged to avoid connecting wallets to unsolicited prompts and to verify all interactions through official channels.
The company has not disclosed the source of the breach but has committed to ongoing security reviews.
Crypto Crime Turns Violent as Illicit Transactions Top $40B in 2024Illicit cryptocurrency activity surged to at least $40.9 billion in 2024, according to Chainalysis, with the number likely to grow as more criminal-linked wallets are identified.
Hacks alone accounted for $2.2 billion in stolen assets, a 21% increase from the previous year.
North Korean-linked groups, including Lazarus and Tradetraitor, were behind over 60% of those thefts, with major incidents like the $300 million hack of Japan’s DMM Bitcoin exchange among their hits.
But the threats go beyond online exploits. Criminal groups are using crypto to fund and conceal a wider range of crimes—from investment scams and AI-enhanced romance frauds to drug trafficking and even physical violence.
In one alarming case on May 13, 2025, the daughter and grandson of Paymium’s CEO were nearly kidnapped in Paris by masked men.
The post CoinMarketCap Hacked, Scrambles to Remove Malicious Wallet Verification Popup appeared first on Cryptonews.
Why this matters
This security story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on CryptonewsRelated market context
Coldcard Security Notice Puts Bitcoin Wallet Entropy Risk Back In Focus
A Coldcard security issue has put Bitcoin hardware-wallet safety back under the microscope after reports that a firmware flaw affe...
Coldcard attack: 25 minutes, 500 wallets, $38M in BTC gone
Someone likely used AI to drain almost 600 BTC, worth $38 million, from roughly 500 dormant wallets yesterday as part of a seed ph...
Coinkite warns Coldcard Mk3 users of firmware flaw that may have compromised wallet seeds
The firmware flaw highlights the critical importance of robust RNGs in hardware wallets, emphasizing the need for vigilant securit...
Trust wallet surpasses MetaMask and phantom in 24-hour HyperliquidX revenue
The shift in wallet revenue dynamics may boost interest in Hyperliquid, influencing market sentiment and future valuation predicti...
IRS Warns Fake Crypto Letters Target Wallets and Personal Data
Fraudsters are mailing counterfeit IRS notices that direct cryptocurrency holders toward a fabricated compliance portal designed t...
Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen
Bitcoin Magazine Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen The popular Bitcoin hardware wallet...