CoinMarketCap briefly hacked to drain crypto wallets via fake Web3 popup
The well-known cryptocurrency price tracking website CoinMarketCap experienced a supply chain hack that left users vulnerable to a wallet drainer campaign that stole their cryptocurrency.
Visitors to CoinMarketCap started seeing Web3 popups requesting that they link their wallets to the website on Friday night, January 20. However, a rogue software depleted visitors' cryptocurrencies when they connected their wallets.
The business subsequently acknowledged that threat actors had introduced malicious JavaScript onto the website by exploiting a flaw in the "doodle" image on the homepage.
Our security team discovered a flaw in a doodle image that was shown on our homepage on June 20, 2025. According to a statement made on X, this doodle artwork included a link that, when seen on our...

