A recently discovered vulnerability in CoinMarketCap's front-end system was exploited by hackers, who used a seemingly innocuous doodle image to inject malicious code and trigger fake wallet verification pop-ups across the website. The security incident, confirmed by CoinMarketCap, involved the use of its backend API to deliver a manipulated JSON payload that embedded JavaScript into the homepage, as reported by blockchain security firm Coinspect Security.
This script prompted an unauthorized request for users to 'Verify Wallet', a tactic aimed at deceiving visitors into granting access to their cryptocurrency holdings. According to the blockchain security firm, the attack was traced back to the platform's rotating 'doodles' feature, which allowed the attackers to embed the malicious code without altering the site's core infrastructure. The phishing pop-up was active for a brief period before being removed by CoinMarketCap's team.
In a statement posted on social media, CoinMarketCap said, 'Upon discovery, we acted immediately to remove the problematic content. Comprehensive measures have been implemented to isolate and mitigate the issue.' However, the company has not disclosed the number of users who encountered the pop-up or whether any wallets were compromised as a result of the breach.