Hacker Attack on Cointelegraph: Fake Token Steals Wallet
Cointelegraph suffered a hacker attack that displayed a fake CTG pop-up inducing users to link wallets, causing funds to be stolen.
Cointelegraph suffered a hacker attack that displayed a fake CTG pop-up inducing users to link wallets, causing funds to be stolen.

Get the latest news, learn from experts, discover new tools, and find inspiration right in your inbox.
No spam. Unsubscribe anytime.
A powerful documentary on how Bitcoin and blockchain are reshaping money, power, and geopolitics—from El Salvador’s Bitcoin experiment and Europe’s regulatory revolution to the rise of decentralized finance and the new global financial order.
The well-known cryptocurrency news source Cointelegraph has confirmed a security breach of the front-end that exposed its users to a scam on 22 June that could empty their digital wallets.
Users were tricked into linking their digital wallets via an attack that consisted of a fake 'Cointelegraph Token (CTG)' pop-up promoting a counterfeit Initial Coin Offering (ICO).
The incident was first detected by the blockchain security tool Scam Sniffer, which revealed how the attackers were attempting to gain illicit access to the wallets. Once connected, the wallets could be quickly emptied of funds.
Scam Sniffer stated on X:
The attack was generated by a dangerous JavaScript payload delivered via the website's advertising system. The suspicious code appeared to originate from a domain similar to AdButler. However, the domain had recently been registered and was linked to a malicious script hidden within a banner ad.
Cointelegraph quickly intervened by warning users not to interact with any pop-ups advertising CTG tokens or claiming to be part of an ICO airdrop. The platform highlighted the problem in a public statement, stressing that an active investigation was underway and that steps were being taken to remove the malicious code.
Cointelegraph also advised users not to enter personal information or link wallets in response to any pop-ups or invitations that appeared on the site.
A Similar Attack Also Hits CoinMarketCap
Two days before this attack, a hack that was almost identical to CoinMarketCap. The front-end breach suffered by the crypto data aggregator on 20 June led to the appearance of a fake pop-up asking users to link their wallet on the homepage.
CoinMarketCap noted that the problem was caused by a 'doodle' image that contained illegal JavaScript code capable of temporarily altering the site's interface. Although the distribution methods were slightly different, both attacks used JavaScript-based exploits from misleading advertisements and pop-ups, suggesting a possible coordinated campaign targeting high-traffic crypto platforms.
"On 20 June 2025, our security team identified a vulnerability related to a doodle image displayed on our homepage. This image contained a link that activated malicious code via an API call, generating an unexpected pop-up for some users visiting our homepage," the CoinMarketCap officials explained.
Changpeng Zhao, former CEO of Binance, commented on the attack on CoinMarketCap stating that 39 users were affected and lost a total of $18,570. Zhao warned that these incidents highlight a growing risk posed by fraudsters exploiting trusted crypto platforms.
Both platforms are working to strengthen ad-related security systems and prevent similar attacks in the future, while investigations continue.
Read Next
LastPass Hack: 35 million in crypto laundered by Russian hackers
An investigation by TRM Labs reveals how Russian hackers laundered more than $35 million in cryptocurrency stolen from LastPass users.
Hack Trust Wallet at Christmas: $7 million stolen
A critical bug in Trust Wallet's Chrome extension caused the theft of around $7 million in crypto. Here's what happened, who is at risk, and how to protect your funds.
Solana withstands record 6 Tbps DDoS attack
Solana overcame one of the largest DDoS attacks in history without downtime, marking a breakthrough in network resilience.
North Korean Hackers Steal $300M with Fake Crypto Meetings
Cyber criminals linked to North Korea embezzled over $300 million from the crypto sector using fake video meetings, compromised Telegram accounts and advanced malware.