Data Breaches

Hacked Ethereum Foundation Account Used to Send 35,000 Phishing Emails

A threat actor sent over 35,000 phishing emails after hacking into Ethereum Foundation’s account on a mailing list platform.

A threat actor sent over 35,000 phishing emails after hacking into Ethereum Foundation's account on a mailing list platform.

A threat actor hacked into Ethereum Foundation’s account on a mailing list platform and used it to send email phishing lures to more than 35,794 addresses.

The phishing emails, which came from the legitimate updates@blog.ethereum.org email address, promoted a Lido scam and contained a link to a malicious site designed to drain the visitors’ wallets.

“This website had a crypto drainer running in the background, and if a user initiated their wallet and signed the transaction requested by their website their wallet would have been drained,” the Ethereum Foundation said in a notice.

According to the organization, the threat actor leveraged their access to the platform to export 3,759 email addresses representing the foundation blog’s mailing list and to import their own list of emails to be used in the phishing campaign.

The foundation says that 81 of the exported email addresses were not known to the threat actor, while the others were already in their data set.

“Analyzing on-chain transactions made to the threat actor between the time they sent out the email campaign and the time the malicious domain got blocked, appear to show that no victims lost funds during this specific campaign sent by the threat actor,” the Ethereum Foundation said.

Advertisement. Scroll to continue reading.

The organization said it took immediate steps to prevent the threat actor from sending additional emails, blocked the hackers’ access to the platform, sent notifications to alert users to not click on the malicious URL, and submitted the link to be blocked by web3 wallet providers and Cloudflare.

“As we continue working on this incident, we have taken additional measures such as migrating some mail services to other providers, to further help reduce the risk of this happening again,” the Ethereum Foundation said.

Related: Malware Sandbox Any.Run Targeted in Phishing Attack

Related: Autodesk Drive Abused in Phishing Attacks

Related: Shield and Visibility Solutions Target Phishing From Inside the Browser

Related: Open Redirect Flaws in American Express and Snapchat Exploited in Phishing Attacks

Related Content

Artificial Intelligence

Researchers uncovered two campaigns embedding indirect prompt injections in malicious websites to exploit autonomous AI agents browsing the web.

Cybercrime

The decentralized prediction market said hackers targeted some of its users through a compromise of a third-party vendor.

Malware & Threats

CryptoBandits uses a local SOCKS5 proxy for traffic routing, blending data theft with remote code execution.

Malware & Threats

Masquerading as popular cryptocurrency wallets, the apps can hijack recovery phrases and private keys.

Cybercrime

The hackers targeted LayerZero’s DVN, compromising certain RPCs and DDoSing others to trigger failover to the poisoned infrastructure.  

Cybercrime

Law enforcement in the US, UK and Canada identified more than $45 million in cryptocurrency and froze $12 million.

Mobile & Wireless

The security hole affected an EngageLab SDK and it was reported by Microsoft to the vendor one year ago.

Cybercrime

A hacker transferred more than 50 bitcoin from the Bitcoin ATM operator’s wallets after stealing credentials. 

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version