Close Menu
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Categories
  • Altcoins (2,058)
  • Analysis (2,223)
  • Bitcoin (2,823)
  • Blockchain (1,715)
  • DeFi (2,029)
  • Ethereum (2,029)
  • Event (69)
  • Exclusive Deep Dive (1)
  • Landscape Ads (2)
  • Market (2,074)
  • Press Releases (10)
  • Reddit (1,474)
  • Regulation (1,943)
  • Security (2,696)
  • Thought Leadership (3)
  • Videos (43)
Hand picked
  • BitMine (BMNR) Buys $821M Ether, now holding over $13B ETH, only half way to their target.
  • Coinbase is betting big: will this public AI and stablecoin beast ship billions?
  • Last week, crypto hit record inflows at $5.95 billion: CoinShares
  • Kalshi raises $300 million at a $5 billion valuation: NYT
  • New Crypto Coin Mutuum Finance (MUTM) to Launch Lending Protocol V1 in Q4 2025
We are social
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Facebook X (Twitter) Instagram
  • About us
  • Disclaimer
  • Terms of service
  • Privacy policy
  • Contact us
Facebook X (Twitter) Instagram YouTube LinkedIn
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Events
Altcoin ObserverAltcoin Observer
Home»Ethereum»blog.ethereum.org Mailing List Incident | Ethereum Foundation Blog
Ethereum

blog.ethereum.org Mailing List Incident | Ethereum Foundation Blog

August 9, 2024No Comments
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


On 2024-06-23 at 00:19 UTC, a phishing email was sent to 35,794 email addresses by updates@blog.ethereum.org with the following content

Users who clicked on the link in the email were redirected to a malicious website:

This website had a cryptocurrency drainer running in the background, and if a user initiated their wallet and signed the transaction requested by their website, their wallet would have been drained.

Our internal security team immediately launched an investigation to help determine who launched the attack, what the objective of the attack was, when it occurred, who was affected, and how it occurred.

Some of the first steps taken were:

  • Prevented the threat actor from sending additional emails.
  • I sent notifications via Twitter and email not to click on the link in question.
  • Closed the malicious access path that the threat actor used to gain access to the mailing list provider.
  • I submitted the malicious link to various blacklists, and it was subsequently blocked by the majority of Web3 wallet providers and Cloudflare.

Our investigation into the attack showed that:

  • The malicious actor imported his own large email list into the mailing list platform to use in the phishing campaign.
  • The threat actor exported the email addresses from the blog’s mailing list, which totaled 3,759 email addresses.
  • When we compared the emails from the mailing list that the threat actor had imported, we were able to see that the blog mailing list contained 81 email addresses that the threat actor was not previously aware of, and the rest were duplicate addresses.
  • Analysis of the on-chain transactions made to the threat actor between the time they sent the email campaign and the time the malicious domain was blocked, appears to show that no victims lost funds during this specific campaign sent by the threat actor.

As we continue to work through this incident, we have taken additional measures such as migrating some email services to other providers, to further reduce the risk of this happening again.

We are deeply sorry that this incident occurred and are working diligently with our internal security team as well as external security teams to help resolve and further investigate this incident.

Any questions can be addressed to security@ethereum.org.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleHottest Cryptocurrencies on AVAlanche Today – Landwolf, GURS, Meat
Next Article Blockchain.com Integrates Prove Identity to Streamline KYC Process

Related Posts

Ethereum

Grayscale stakes 857,600 Ethereum worth $3.83 billion as institutional trust rises

October 10, 2025
Ethereum

Will BoE “exemptions” increase stablecoin rails in BTC and ETH?

October 9, 2025
Ethereum

Ethereum doubles down on privacy with new “Kohaku” wallet ahead of Devcon

October 9, 2025
Add A Comment
Leave A Reply Cancel Reply

Single Page Post
Share
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Featured Content
Event

Moscow Hosts COINCRAFT 2.0: The Ultimate Crypto Forum of the Season

October 8, 2025

MOSCOW, October 2025 — The wait is almost over! On October 15–16, 2025, the VKontakte…

Event

The Digital Euro vs. Stablecoins: The Future of Money is Debated at MERGE Madrid

October 7, 2025

The Digital Euro vs. Stablecoins: The Future of Money Is Debated at MERGE Madrid  The…

1 2 3 … 56 Next
  • Facebook
  • Twitter
  • Instagram
  • YouTube

Last week, crypto hit record inflows at $5.95 billion: CoinShares

October 10, 2025

DEXE Nears KEY Support as $5.3M Selloff Triggers Price Drop!

October 10, 2025

Coinbase and Mastercard in advanced talks to acquire British stablecoin BVNK

October 10, 2025
Facebook X (Twitter) Instagram LinkedIn
  • About us
  • Disclaimer
  • Terms of service
  • Privacy policy
  • Contact us
© 2025 Altcoin Observer. all rights reserved by Tech Team.

Type above and press Enter to search. Press Esc to cancel.

bitcoin
Bitcoin (BTC) $ 120,216.21
ethereum
Ethereum (ETH) $ 4,262.22
tether
Tether (USDT) $ 1.00
bnb
BNB (BNB) $ 1,236.10
xrp
XRP (XRP) $ 2.80
solana
Solana (SOL) $ 219.49
usd-coin
USDC (USDC) $ 1.00
dogecoin
Dogecoin (DOGE) $ 0.24656
staked-ether
Lido Staked Ether (STETH) $ 4,264.84
tron
TRON (TRX) $ 0.333327