Mailer Lite hacker impersonates crypto firms, draining $600,000 with phishing emails
Quick Take An exploiter abused a vulnerability in a digital marketing platform to mimic seemingly legitimate emails that actually included links to wallet drainer sites, Blockaid found. The attack targeted CoinTelegraph, WalletConnect, Token Terminal and De.Fi, according to crypto sleuth ZachXBT.
Digital marketing platform Mailer Lite was the victim of a phishing attack that resulted in the loss of over $600,000, according to the web3 security and privacy firm Blockaid.
The exploiter used a vulnerability in Mailer Lite to mimic web3 firms sending seemingly legit emails that actually contained malicious links to wallet drainer sites, Blockaid explained in a social media thread Tuesday, adding that "attackers took advantage of the fact that Mailer Lite had previously been given permission to send email on behalf of these site’s domains, enabling them to craft emails that seemed to be coming from these organizations."
"Specifically, they used 'dangling dns' records which were created and associated with Mailer Lite (previously used by these companies)," it continued. "After closing their accounts these DNS records remain active, giving attackers the opportunity to claim and impersonate these accounts."
CoinTelegraph, WalletConnect, Token Terminal and De.Fi were among the platforms targeted by the phishing attack, according to the crypto sleuth ZachXBT .
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Trump’s Republican allies unsettled by Elon Musk’s D.O.G.E
Share link:In this post: Elon Musk’s D.O.G.E. has gutted the CFPB, firing employees, shutting down enforcement, and wiping the agency’s name off its headquarters—leaving Trump allies worried it could backfire in court. Russell Vought and other Trump officials fear Elon’s reckless approach could bring lawsuits, allowing the CFPB to survive instead of being quietly dismantled. Government employees are suing the Trump administration anonymously, afraid Elon’s attacks on X and mass firings could put them at ri
Netflix faces backlash for using AI-generated voice of Gabby Petito
Share link:In this post: Netflix used AI to recreate Gabby Petito’s voice in its new docuseries, and people are calling it disturbing and unethical. Viewers slammed Netflix online, saying AI shouldn’t be used to digitally recreate a murder victim’s voice for a documentary. Gabby’s family approved it, but experts argue that murder victims don’t get a say in how their voice is used after death.
Vitalik Buterin joins the resistance against the UK government’s push for Apple user data
Share link:In this post: Vitalik Buterin criticized the UK government for its recent demands for backdoor access to Apple user data. This will be the first time Apple is disabling its data security tool. Apple reassures users that some data, such as health app data, passwords, and communications on iMessage and FaceTime, will remain end-to-end encrypted.
President Trump Declares End to Biden’s Crypto War, Pledges US Bitcoin Dominance
Trending news
MoreCrypto prices
More








