The Ethereum Foundation email account has been hacked to promote a scam disguised as a Lido betting scheme.
according to New AdvertisementThe Ethereum Foundation email account used to send official updates was hacked on June 23.
The attackers used [email protected] Email address to send phishing emails to 35794 addresses.
In the email, users found an announcement that the Ethereum Foundation had partnered with Lido Decentralized Autonomous Organization (LidoDAO). As part of the partnership, a 6.8% return on staked Ether (stETH), Wrapped Ether (WETH), or Ether
ETH deposits are now available.
“The collaboration leverages the strengths of both organizations to provide deep liquidity and competitive rewards, enhancing your sharing experience with over 100 integrations,” reads an excerpt from the announcement.
She also added that the storage service will be “protected and verified” by the Ethereum Foundation.
At the bottom of the ad was a “Start Betting” button. Clicking on it would redirect users to a website created by the attackers.
The malicious site, dubbed “Staking Launchpad,” reportedly had a cryptocurrency draining program running in the background. Furthermore, the site was designed to look professional.

Anyone who clicks on the “Bet” button on the website will be asked to approve the transaction in their wallet. If approved, all funds will be drained from the user’s account.
No money lost
At the time of writing, the organization said it had gained control of the compromised email address. According to the organization’s investigation, no money was lost in the attack.
“Analysis of the on-chain transactions conducted by the threat actor between the time they sent the email campaign and the time the malicious domain was blocked appears to indicate that no victims lost money during this specific campaign sent by the threat actor,” the organization noted.
The organization also discovered that the hacker had uploaded a database containing email addresses that were not on the organization’s subscriber list. As a result, many users who had not subscribed also received a phishing email.
The attacker also exported a “blogger email list” containing 3,759 email addresses. However, the list contained only 81 email addresses, the rest were “duplicate addresses.”
Accordingly, it was estimated that the attack compromised the email addresses of 81 subscribers.
Meanwhile, the organization has also reached out to several wallet providers, blacklists, and DNS provider Cloudflare, urging these platforms to warn users if they are redirected to the malicious website.
It is no stranger to the cryptocurrency industry being hit by email phishing schemes.
In early June, several key figures in the cryptocurrency world emerged. Be warned about a prominent email vendor Users were exposed to the risk of receiving fraudulent messages promoting fake airdrops. Before that, Email addresses of several prominent cryptocurrency-related entities They were used to send phishing emails.



















.jpg)


