Decentralized blockchain Ethereum had 35,794 users exposed to a cryptocurrency draining scheme following the compromise of its mailing list provider last week, BleepingComputer reports. Attackers leveraging a combination of their email address list and 3,759 additional addresses from the mailing list, only 81 of which were new, sent phishing emails via '[email protected]' promoting a partnership with Lido DAO that included a link, which when clicked redirected to a legitimate-looking site that proceeded to drain cryptocurrency within connected wallets, according to Ethereum. Investigation into the incident, which has not compromised any of the recipients, is still underway but Ethereum has already moved to block further phishing email delivery and avert potential compromise of other Web3 wallet providers through link submissions to blocklists. Aside from alerting users regarding the phishing scheme, Ethereum also disclosed performing selective email service migration and other measures to curb similar attacks in the future.
Email security, Networking, Network Security![](https://image-optimizer.cyberriskalliance.com/unsafe/1920x0/https://files.cyberriskalliance.com/wp-content/uploads/2023/08/Webroot_Penetesting_Blog-image-02-1.jpeg)
Over 35K exposed to crypto draining scheme after Ethereum mailing list hack
![](https://image-optimizer.cyberriskalliance.com/unsafe/1920x0/https://files.cyberriskalliance.com/wp-content/uploads/2023/08/Webroot_Penetesting_Blog-image-02-1.jpeg)
An In-Depth Guide to Network Security
Get essential knowledge and practical strategies to fortify your network security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds