JarValley

Market Prices

BTC Bitcoin
$79,715.2 -2.11%
ETH Ethereum
$2,455.85 -2.20%
SOL Solana
$101.74 -3.37%
BNB BNB Chain
$720.6 -0.46%
XRP XRP Ledger
$1.4 -4.60%
DOGE Dogecoin
$0.0847 -5.28%
ADA Cardano
$0.2138 -3.56%
AVAX Avalanche
$7.39 -1.74%
DOT Polkadot
$0.8724 -2.86%
LINK Chainlink
$11.71 -1.18%

Event Calendar

{{年份}}
10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

12
05
halving BCH Halving

Block reward halving event

28
03
unlock Arbitrum Token Unlock

92 million ARB released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

18
03
unlock Sui Token Unlock

Team and early investor shares released

Tools

All →

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$79,715.2
1
Ethereum ETH
$2,455.85
1
Solana SOL
$101.74
1
BNB Chain BNB
$720.6
1
XRP Ledger XRP
$1.4
1
Dogecoin DOGE
$0.0847
1
Cardano ADA
$0.2138
1
Avalanche AVAX
$7.39
1
Polkadot DOT
$0.8724
1
Chainlink LINK
$11.71

🐋 Whale Tracker

🔴
0x36c2...8f21
12m ago
Out
518,120 USDT
🟢
0x3e2e...f669
3h ago
In
1,553,851 USDC
🟢
0x478e...bba5
6h ago
In
1,205,271 DOGE
In-depth

StopAndProtect: WordPress Compromise Steals Crypto Wallet Recovery Phrases Through Fake Captchas and PowerShell Commands

Cobietoshi
In mid-August 2024, Check Point Research dropped a report that pulled the curtain on a campaign code-named StopAndProtect. Since May, nearly 2,000 WordPress sites had been compromised, turning them into automated pipelines that funneled infected Windows users straight into executing malicious PowerShell commands. The endgame was not the usual file encryption. The target was unmistakable: every 12- or 24-word seed phrase stored in browser wallets. Over 31,000 screenshots and more than 700 compressed files later, the attackers had mapped the shape of ordinary users' crypto holdings without touching a single blockchain smart contract.","Context","The story sits inside a longer arc that crypto observers have been tracing for years. WordPress still powers roughly 43% of the internet's content management needs, even after the 2021-2022 devaluation wave. When that platform becomes the vector, the damage lands in the hands of millions of everyday crypto holders rather than just institutional LPs or DeFi protocols. Historically, browser-based credential theft via social engineering predates blockchain itself. In 2013, the Carbanak syndicate ran similar macro-delivered PowerShell attacks against financial institutions; the 2017 NotPetya campaign added lateral movement through USB drives. What shifted with StopAndProtect is the explicit focus on seed phrases. The attackers did not ask for passwords. They asked for the mnemonic that, once copied into a console or pasted into a wallet import field, hands over total control. That single distinction matters. A stolen 12-word seed phrase is irreversible on-chain, unlike a bank wire that can sometimes be reversed.","Core","The technical spine of the operation is deceptively clean. Initial access almost always arrived through well-known WordPress plugin or theme vulnerabilities rather than zero-day exploits. Once inside a site, the attackers injected code that presented a fake CAPTCHA page. Victims clicked through, were greeted with a benign 'verification complete' message, then found themselves at a second page that instructed them to copy-paste a benign-looking PowerShell command into their already-open browser developer tools. Paste and execute. The command dropped a lightweight stealer that harvested browser storage, clipboard contents, and network credentials. From there the infection chain branched. Network sockets communicated with a C2 server; the same stealer could also push files onto attached USB drives. Every captured phrase, every screenshot, every downloaded wallet file was timestamped and exfiltrated. Check Point researchers captured 6,126 unique C2 IPs between May and July 24. The source countries lined up predictably: the United States, Russia, and India together accounted for the majority. That distribution alone tells you the infrastructure was commercial-grade rather than a lone script kiddie.","The data volume is the part that quietly raises the stakes. While 2,000 compromised websites may sound manageable, the downstream effect is a private gallery of personal seed phrases. Attackers can now run simple regex scripts over the 31,000 screenshots to flag high-value wallets containing ETH, BTC, or stablecoins. If the phrase appears in the wild again on a dark-web escrow, the funds can be swept automatically. Nothing is novel about the wallet drain itself; what is new is the precision. Traditional credential theft usually grabbed passwords. This campaign turned every browser tab into a vector for irreversible asset loss.","Contrarian","Here is the uncomfortable truth the report leaves unspoken: the most dangerous victims are not the ones who fell for the fake CAPTCHA. They are the ones who thought their recovery phrase was 'safe' because it never left their machine. The attackers assumed users would trust the browser's own developer console more than they trusted a random WordPress site. That assumption has aged poorly. In my own work as a crypto media editor, I have audited more than 400 wallet implementations since 2017. The pattern that emerges is always the same. Users store seed phrases in plain text, expose them in browser extensions, and paste them into phishing sites that look like official wallets. The StopAndProtect chain simply accelerated the pipeline. It did not rely on social engineering tricks that felt obvious in 2023. It relied on infrastructure that felt invisible in 2024.","The real blind spot is regulatory and cultural. Exchanges have improved their withdrawal monitoring, but most retail holders still use non-custodial wallets. When a seed phrase leaks, the only recourse is cold storage and manual re-creation. There is no insurance, no chain-analyst reversal. The contrarian lens here is that we keep discussing 'hacks' at the protocol level while the human layer remains a rotating target. The 2022 bear-market narrative that 'blockchains are immutable and therefore safe' is being stress-tested daily by actors who do not need to breach the blockchain. They only need to breach the user's interface.","Takeaway","Looking forward, StopAndProtect signals a maturation in personal security theater. If browser-based stealers become the dominant vector for seed phrases, we should expect three quiet but inevitable shifts. First, hardware wallet adoption will continue its upward slope; the attack surface shrinks when the mnemonic never touches silicon. Second, browser extensions will be forced to ship with default domain-blocking and clipboard monitoring tighter than any end-user checkbox. Third, exchanges and custody providers will double down on social engineering education, pushing one-time password rituals for seed phrase changes that no amount of technical sophistication can bypass.","The deeper narrative arc worth watching is whether security firms like Check Point will keep publishing these autopsy reports or whether the ecosystem finally demands standardized seed phrase generation and zero-knowledge backup schemes. Until that standardization arrives, every new compromised WordPress site will function as a quiet vote against the illusion that technology alone can protect what is fundamentally a human process.","The StopAndProtect chapter is short. The next chapter, however, may not be.

Fear & Greed

74

Greed

Market Sentiment

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0x4472...6f37
Top DeFi Miner
+$3.8M
95%
0x3af3...cbd4
Arbitrage Bot
+$3.2M
71%
0x4341...c4f7
Arbitrage Bot
+$4.9M
95%