{"investigation":{"slug":"cardano","entity_name":"Cardano","trust_score":72,"severity_base":null,"score_modifier":40,"confidence":1,"status":"published","content_type":"investigation","summary":"Cardano (ADA) holders face a persistent and multi-vector threat landscape that includes deepfake giveaway scams impersonating founder Charles Hoskinson, social media account hijackings used to promote fraudulent tokens, phishing campaigns distributing credential-stealing malware disguised as wallet software, and NFT-based wallet drainers. The Cardano Foundation's own X account was compromised in December 2024, resulting in the promotion of a fake token and false regulatory claims. State-sponsored actors including the North Korean Lazarus Group have also targeted ADA holders through the Atomic Wallet supply chain attack.","sections":[{"content":"Scammers have repeatedly used AI-generated and deepfake video technology to impersonate Cardano founder Charles Hoskinson in fake ADA giveaway promotions. In December 2023, a cloned video of Hoskinson allegedly endorsing a giveaway appeared as an advertisement on YouTube crypto content, directing viewers to scan a QR code leading to a fraudulent site. The fake video used Hoskinson's likeness and voice, with the narration stating: 'This giveaway is our way of giving back to the community.' Separately, the Cardano Community official account warned that a fake rewards event had already stolen over 200,000 ADA from victims who connected their wallets. Hoskinson has publicly warned that generative AI deepfakes targeting crypto investors will become increasingly difficult to distinguish from genuine content. The pattern extends beyond Hoskinson: scammers have routinely hijacked large YouTube channels (including accounts with 400,000–650,000 subscribers) to run live-stream giveaway fraud posing as official Cardano announcements. Cardano has issued repeated public statements emphasizing that it will never conduct ADA giveaways or ask users to send funds first.","heading":"Deepfake and AI-Generated Giveaway Scams","sources":[],"severity":"medium"},{"content":"On December 8, 2024, the official X (Twitter) account of the Cardano Foundation was compromised by a threat actor. The attacker used the account to promote a fraudulent Solana-based token branded 'ADAsol,' falsely claiming it was the successor to the native ADA token. Concurrently, the hacked account posted a false announcement asserting that the U.S. Securities and Exchange Commission had initiated legal action against the Cardano Foundation, and that the Foundation would cease support for ADA to comply with regulatory requirements. The fabricated SEC news caused a brief 4% decline in the ADA price. The fake ADAsol token generated approximately $500,000 in trading volume before collapsing by 99%. Cardano founder Charles Hoskinson confirmed the breach publicly and urged the community to disregard the posts. The Foundation regained control of the account by December 12, 2024, and confirmed no other systems were affected. Blockchain investigator ZachXBT noted the attack was consistent with a broader pattern of X account phishing campaigns where attackers sent emails disguised as official X team communications to steal credentials.","heading":"Cardano Foundation X Account Compromise — December 2024","sources":[],"severity":"medium"},{"content":"ADA holders have been targeted by multiple phishing campaigns impersonating popular Cardano wallets. In a campaign identified around late 2024 and early 2025, attackers distributed a fraudulent email titled 'Eternl Desktop Is Live' referencing legitimate Cardano ecosystem terms such as Atrium, Diffusion Staking Basket, and NIGHT/ATMA token rewards to appear credible. The download link pointed to an unverified domain (download.eternldesktop.network) serving a malicious installer named Eternl.msi (23.3 MB). Analysis of the installer revealed it contained a hidden LogMeIn GoTo Resolve remote management tool; upon execution it dropped an executable named unattended-updater.exe which established persistent remote access to the victim machine without user awareness, transmitting system data to attacker-controlled infrastructure. In April 2024, the official Lace wallet team issued alerts about fake versions of their application appearing on the Apple App Store and Google Play Store. In March 2026, a fraudulent site impersonating the Lace wallet (lacedesktop.io) was flagged alongside phishing emails referencing a non-existent 'Lace Desktop 2.0' update. Additionally, a fake token migration email campaign in October 2024 targeted ADA holders by referencing the Chang hard fork, directing victims to connect their wallets to a fraudulent site to complete an alleged token migration. These campaigns are characterized by technically sophisticated social engineering that exploits users' awareness of real Cardano development milestones.","heading":"Phishing Campaigns and Malware-Bearing Fake Wallets","sources":[],"severity":"medium"},{"content":"Cardano users have been targeted by scam NFTs sent directly to their wallets as vectors for theft. Ledger has documented this attack pattern, in which NFTs containing fraudulent instructions or links are airdropped to ADA holders without consent. A notable instance involved the Berry Pool scam in December 2023, where delegators received an NFT falsely promising additional ADA rewards through a fabricated reward event. Users who connected their wallets and signed transactions on the associated scam website lost funds exceeding 200,000 ADA in aggregate. Separately, a Cardano community member issued a broader alert warning ADA holders against clicking links embedded in unexpected NFTs, as these typically lead to wallet-draining websites. Ledger's official support documentation advises users to avoid interacting with any unsolicited NFTs received in their Cardano wallets.","heading":"NFT-Based Wallet Draining Attacks","sources":[],"severity":"medium"},{"content":"On June 3, 2023, users of Atomic Wallet — a non-custodial multi-currency wallet that supported Cardano — suffered losses exceeding $35 million across multiple cryptocurrencies, including Bitcoin, Ethereum, Litecoin, XRP, ADA, Dogecoin, and Tezos. The attack affected approximately 1% of Atomic Wallet's five million users, with the top five victims accounting for roughly $18 million of the total loss. Blockchain analytics firms Elliptic attributed the attack with high confidence to the Lazarus Group, a North Korean state-sponsored hacking organization, based on the laundering patterns used, the involvement of the Sinbad cryptocurrency mixer (previously used by Lazarus in the 2022 Harmony Horizon Bridge hack), and the movement of funds into wallets linked to prior Lazarus operations. The precise attack vector was never officially disclosed by Atomic Wallet, though researchers speculated it involved compromise of private key storage. This incident represents one of the most significant state-actor threats to Cardano holders due to the volume of ADA held by Atomic Wallet users at the time.","heading":"State-Sponsored Targeting via Atomic Wallet (Lazarus Group)","sources":[],"severity":"medium"},{"content":"Beyond the Cardano Foundation incident, ADA-branded scams have proliferated across multiple social media platforms through a sustained pattern of account hijacking and impersonation. Hacked Twitter accounts belonging to celebrities including actors from 'How I Met Your Mother' have been used to promote Cardano ADA giveaway scams. YouTube channel hijackings have been documented since at least July 2020, with attackers renaming captured channels to 'Cardano' or 'Charles Hoskinson' and running live-stream fraud. ZachXBT tracked a broader campaign in 2024 in which a single threat actor compromised more than 15 high-profile X accounts — including Kick, Cursor, and others — to promote fake Solana-based tokens using the same phishing-email credential-theft method used against the Cardano Foundation. This pattern indicates that ADA's brand recognition and community size make it a recurring target for opportunistic social engineering across platforms.","heading":"Broader Social Media Impersonation and Account Hijacking Pattern","sources":[],"severity":"medium"}],"timeline":[{"date":"2020-07","event":"Cardano issues first public warning about fake ADA giveaway scams on YouTube, as hacked channels begin hosting fraudulent Hoskinson livestreams.","source":"","source_url":"https://cointelegraph.com/news/cardano-warns-of-youtube-scams-promoting-fake-ada-giveaways","date_original":"2020-07-01"},{"date":"2021-07","event":"YouTube channel of influencer Ashkar Techy (650,000 followers) hacked and renamed to promote fake Cardano ADA giveaway livestream.","source":"","source_url":"https://cryptocoin.news/news/scam-alert-new-series-of-hacks-against-youtube-channels-impersonating-official-cardano-announcements-53509/","date_original":"2021-07-01"},{"date":"2021-09-20","event":"Cardano reiterates it will 'never give away ADA' following a new wave of YouTube giveaway scam attacks targeting ADA holders.","source":"","source_url":"https://en.cryptonomist.ch/2021/09/20/cardano-never-give-away-ada/"},{"date":"2023-06-03","event":"Atomic Wallet suffers a $35M+ hack attributed by Elliptic to the North Korean Lazarus Group; ADA is among the stolen cryptocurrencies across multiple victims.","source":"","source_url":"https://www.bleepingcomputer.com/news/security/lazarus-hackers-linked-to-the-35-million-atomic-wallet-heist/"},{"date":"2023-12-14","event":"Cardano community warns of fake Berry Pool NFT rewards scam draining over 200,000 ADA from victims who connected wallets to a fraudulent site.","source":"","source_url":"https://cryptopotato.com/watch-out-cardano-ada-users-alerted-to-stay-away-from-this-dangerous-scam/"},{"date":"2023-12-15","event":"AI-generated deepfake video of Charles Hoskinson endorsing a fake ADA giveaway surfaces as a YouTube advertisement, directing victims to a fraudulent website.","source":"","source_url":"https://thecryptobasic.com/2023/12/15/scammers-promote-fake-ada-giveaway-using-ai-cloned-video-of-cardano-founder/"},{"date":"2024-04","event":"Lace wallet team issues alert about fake Lace wallet apps on Apple App Store and Google Play Store designed to steal recovery phrases from ADA holders.","source":"","source_url":"https://u.today/security-alert-ada-users-targeted-by-fake-cardano-wallet-updates-with-malware","date_original":"2024-04-01"},{"date":"2024-10-03","event":"Fraudulent email campaign targets ADA holders with fake Chang hard fork token migration instructions, directing victims to wallet-draining sites.","source":"","source_url":"https://www.cryptotimes.io/2024/10/03/fake-cardano-token-migration-emails-target-ada-holders/"},{"date":"2024-12-08","event":"Cardano Foundation's official X account is compromised; hackers promote fake 'ADAsol' token generating $500K in volume before crashing 99%, and post false SEC lawsuit claim causing a 4% ADA price drop.","source":"","source_url":"https://cryptobriefing.com/cardano-foundation-hacked-false-sec-claims/"},{"date":"2024-12-12","event":"Cardano Foundation regains control of its X account; confirms no other systems were affected by the breach.","source":"","source_url":"https://u.today/cardano-foundation-addresses-x-account-hack-heres-what-happened"},{"date":"2025","event":"Fake 'Eternl Desktop' phishing campaign distributes malware-laden installer (Eternl.msi) embedding a LogMeIn remote access tool to gain persistent unauthorized access to Cardano users' machines.","source":"","source_url":"https://cybersecuritynews.com/potential-wallet-phishing-campaign-targets-cardano-users/","date_original":"2025-01-01"},{"date":"2026-03-24","event":"Cardano Lace wallet team flags fraudulent site lacedesktop.io and fake 'Lace Desktop 2.0' phishing emails circulating within the ADA community.","source":"","source_url":"https://u.today/security-alert-ada-users-targeted-by-fake-cardano-wallet-updates-with-malware"}],"sources_used":[],"source_tags":["etherscan","zachxbt"],"addresses":[],"reviewed":true,"reviewed_by":null,"model_used":"claude-sonnet","created_at":"2026-05-04T16:05:01.924098+00:00","updated_at":"2026-08-29T01:34:58.993+00:00"}}