Hacker Attack on Cointelegraph: Fake Token Steals Wallet
Cointelegraph suffered a hacker attack that displayed a fake CTG pop-up inducing users to link wallets, causing funds to be stolen.
Cointelegraph suffered a hacker attack that displayed a fake CTG pop-up inducing users to link wallets, causing funds to be stolen.

Get the latest news, learn from experts, discover new tools, and find inspiration right in your inbox.
No spam. Unsubscribe anytime.
A powerful documentary on how Bitcoin and blockchain are reshaping money, power, and geopolitics—from El Salvador’s Bitcoin experiment and Europe’s regulatory revolution to the rise of decentralized finance and the new global financial order.
The well-known cryptocurrency news source Cointelegraph has confirmed a security breach of the front-end that exposed its users to a scam on 22 June that could empty their digital wallets.
Users were tricked into linking their digital wallets via an attack that consisted of a fake 'Cointelegraph Token (CTG)' pop-up promoting a counterfeit Initial Coin Offering (ICO).
The incident was first detected by the blockchain security tool Scam Sniffer, which revealed how the attackers were attempting to gain illicit access to the wallets. Once connected, the wallets could be quickly emptied of funds.
Scam Sniffer stated on X:
The attack was generated by a dangerous JavaScript payload delivered via the website's advertising system. The suspicious code appeared to originate from a domain similar to AdButler. However, the domain had recently been registered and was linked to a malicious script hidden within a banner ad.
Cointelegraph quickly intervened by warning users not to interact with any pop-ups advertising CTG tokens or claiming to be part of an ICO airdrop. The platform highlighted the problem in a public statement, stressing that an active investigation was underway and that steps were being taken to remove the malicious code.
Cointelegraph also advised users not to enter personal information or link wallets in response to any pop-ups or invitations that appeared on the site.
A Similar Attack Also Hits CoinMarketCap
Two days before this attack, a hack that was almost identical to CoinMarketCap. The front-end breach suffered by the crypto data aggregator on 20 June led to the appearance of a fake pop-up asking users to link their wallet on the homepage.
CoinMarketCap noted that the problem was caused by a 'doodle' image that contained illegal JavaScript code capable of temporarily altering the site's interface. Although the distribution methods were slightly different, both attacks used JavaScript-based exploits from misleading advertisements and pop-ups, suggesting a possible coordinated campaign targeting high-traffic crypto platforms.
"On 20 June 2025, our security team identified a vulnerability related to a doodle image displayed on our homepage. This image contained a link that activated malicious code via an API call, generating an unexpected pop-up for some users visiting our homepage," the CoinMarketCap officials explained.
Changpeng Zhao, former CEO of Binance, commented on the attack on CoinMarketCap stating that 39 users were affected and lost a total of $18,570. Zhao warned that these incidents highlight a growing risk posed by fraudsters exploiting trusted crypto platforms.
Both platforms are working to strengthen ad-related security systems and prevent similar attacks in the future, while investigations continue.
Read Next
North Korean Hackers Steal $300M with Fake Crypto Meetings
Cyber criminals linked to North Korea embezzled over $300 million from the crypto sector using fake video meetings, compromised Telegram accounts and advanced malware.
Hack on WeChat involves the co-founder of Binance
The Binance co-founder's WeChat account was hacked to push the Mubarakah meme coin in a pump-and-dump scheme.
Exploit on Yearn Finance: 2.8 million yETH attack
An 'infinite-mint' attack hit Yearn Finance's yETH, draining 2.8 million from Balancer pools and triggering an abnormal market reaction on the YFI token.
32 Million Upbit Hack: Token Solana to Stars on the Korean Market!
Upbit suspends deposits and withdrawals after a hacker attack that embezzled 32 million in Solana tokens, causing heavy premiums in the Korean market.