Crypto Wallets MetaMask, Phantom Targeted in $500K Phishing Attack: Report
Check Point Research (CPR) has discovered a “massive search engine phishing campaign” that has resulted in at least half a million dollars worth of crypto stolen from users. “Over the past weekend, Check Point Research e...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Check Point Research (CPR) has discovered a “massive search engine phishing campaign” that has resulted in at least half a million dollars worth of crypto stolen from users.
“Over the past weekend, Check Point Research encountered hundreds of incidents in which crypto investors lost their money while trying to download and install well-known crypto wallets or change their currencies on crypto swap platforms like PancakeSwap or Uniswap,” CPR said.
“I just installed the phantom wallet and somehow I ended up downloading the scam,” one Reddit user said, adding, “I am somewhat new to wallets.”
The scam, CPR found, has also been hitting MetaMask and Phantom users, two popular crypto wallets, with scammers mimicking legitimate websites almost perfectly.
“Over the past weekend, researchers from CPR spotted multiple phishing websites that looked like the original website, because the scammers copied its design,” CPR added.
Phantom and MetaMaskFor the Phantom domain, users were encountering phishing domains like “phanton.app” or “phantonn.app,” as opposed to the legitimate “phantom.app.”
The same was true of the scammers’ MetaMask tactics, which saw domains like “MètaMask” appear via Google ad campaigns. In the case of MetaMask, the scammers were also trying to steal user private keys to access their wallets.
“What makes this phishing campaign unique is the fact that the scammers are not sending phishing links via email like traditional phishing scams,” CPR said. “Instead, they are using Google ad campaigns to make their phishing websites appear before the original site when anyone searches the keyword,” the group added.
But what can users do to protect themselves? CPR has provided cautionary steps for crypto users.
These include looking at the first website in your search and ensuring that it is not an ad. Users, CPR suggests, should also never give out their passphrase.
Last but not least, CPR says, “always double-check the URLs.”
Why this matters
This security story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on DecryptRelated market context
Trezor Data Breach Exposes 13,689 Users, Crypto Wallets Remain Safe From Attack
Key Takeaways: Through a leak in the software of its shipping partner ShipMonk, Trezor disclosed private information related to ap...
CyberWallet users have until Aug. 15 before crypto withdrawals become a smart contract recovery job
Crypto company Cyber is telling CyberWallet and Cyber Passkey Wallet users to move their assets ahead of an Aug. 15 shutdown that...
Third Point LLC offloads stake in Lam Research, SEC filing reveals
Third Point's rapid divestment signals a strategic shift towards a more concentrated, tech-focused portfolio amid volatile semicon...
With violent crypto home invasions surging, a data breach exposing over 10,000 Trezor owners puts physical safety on the line
On Aug. 13, Trezor said a breach at the fulfillment provider ShipMonk exposed customer data for about 13,689 hardware wallet buyer...
Ireland’s New AML Strategy Brings ‘Enhanced Checks’ on Private Crypto Wallets
The country's first strategy of its kind also brings stricter due diligence for firms dealing with overseas crypto companies.
MyEtherWallet (MEW) Integrates Ondo Perps, Unlocking 24/7 Leveraged Trading for Onchain Equities, & ETFs.
Los Angeles, United States, August 13th, 2026, Chainwire MyEtherWallet (MEW), the world’s most intuitive digital wallet, today ann...