As a researcher with a background in cybersecurity, I cannot help but be alarmed by the latest news of the Ethereum Foundation’s mailing list being compromised. The incident reported by Tim Beiko is a stark reminder of how vulnerable email automation services can be and the potential harm that comes with it.


As an analyst, I’ve come across information where Ethereum core developer Tim Beiko disclosed that the Ethereum Foundation’s mailing list suffered a data breach. The cause of this unfortunate incident was attributed to a vulnerability in SendPulse, the email automation platform used by the Foundation for managing their emails.

An attacker exploited this to send phishing emails from updates@ethereum.org to subscribers.

Based on the most recent communication from Bieko, I’ve learned that the foundation has imposed new restrictions on their mailing list. They specifically asked users to avoid clicking on any links contained in an email that allegedly originated from this list.

Alert: It appears that the email service provider behind “updates@ethereum.org” mailing list has been hacked. We’re working to contact SendPulse to sort out the problem. In the meantime, avoid clicking on any links received from this email.

Users, too, confirmed receiving fraudulent emails.

Phishing attacks are on the rise, with last year seeing the account of Ethereum co-founder Vitalik Buterin fall victim to scammers. These cybercriminals posted a fraudulent NFT giveaway notice, enticing users to click on a harmful link. The unfortunate consequences saw victims collectively losing approximately $800,000.

Buterin later confirmed that the hack was the result of a SIM swap attack.

Lately, the crypto portfolio tracking platform CoinStats announced that approximately 1,590 of its users’ cryptocurrency wallets had been targeted in a phishing attack, making up around 1.3% of their total wallets. Consequently, the company suspended the use of its application for a while.

Furthermore, Yu Xian, the founder of SlowMist, disclosed that the TON blockchain system has recently attracted the attention of phishers because of its significant growth in 2021.

An executive shared that Telegram accounts created with untraceable phone numbers are more susceptible to cyber assaults.

Read More

2024-06-26 07:14