{"investigation":{"slug":"cointelegraph","entity_name":"Cointelegraph","trust_score":62,"severity_base":null,"score_modifier":18,"confidence":1,"status":"published","content_type":"investigation","summary":"Cointelegraph is a major legitimate cryptocurrency news outlet that has been a victim of two distinct infrastructure compromises. In January 2024, attackers breached its email service provider MailerLite and sent phishing emails to subscribers using Angel Drainer malware, resulting in estimated losses of $580,000 to over $700,000 across affected platforms. In June 2025, attackers separately compromised Cointelegraph's banner advertising system to serve Inferno Drainer-linked pop-ups promoting a fake CTG token airdrop to site visitors.","sections":[{"content":"On January 23, 2024, attackers exploited Cointelegraph's email service provider, MailerLite, to send phishing emails from Cointelegraph's official email domain to its newsletter subscriber list. The attack was part of a coordinated campaign simultaneously targeting WalletConnect, Token Terminal, De.Fi, and Decrypt — all companies that used MailerLite as their email marketing platform. The phishing emails promoted fake token airdrops and directed recipients to malicious decentralized applications (dApps) that utilized Angel Drainer infrastructure to drain connected wallets. Blockchain investigator ZachXBT was among the first to publicly warn of the campaign via his Telegram channel on January 23, identifying a multichain attacker wallet that had already accumulated over $580,000 in stolen assets across hundreds of transactions. Blockaid reported losses exceeding $600,000, while Nansen initially cited $3.3 million — though a substantial portion of that figure consisted of illiquid XBANKING tokens, placing the actual liquid losses closer to $700,000. MailerLite confirmed the breach on approximately January 24, 2024, disclosing that a support team member had been socially engineered into clicking an image linked to a fraudulent Google sign-in page, which yielded credentials for the internal admin panel. MailerLite initially reported 117 accounts were accessed, later revising this to 70, with four accounts used to launch the phishing campaigns. Cointelegraph was one of those four accounts. MailerLite stated it notified affected account holders within 8 hours and began deploying FIDO2 physical authentication keys for staff.","heading":"January 2024 MailerLite Email Infrastructure Compromise","sources":[],"severity":"medium"},{"content":"On approximately June 21-22, 2025, Cointelegraph's front-end banner publishing system was briefly compromised. Attackers injected a malicious JavaScript payload via the site's advertising infrastructure — specifically through a domain resembling AdButler that had been recently registered — to display a deceptive pop-up promoting a fake 'Cointelegraph ICO' and fictitious CTG token airdrop. Users who connected their wallets to the pop-up were subjected to wallet draining via tooling linked to Inferno Drainer, a Drainer-as-a-Service operation. Security researchers at Scam Sniffer and Help Net Security attributed the attack vector to the ad delivery layer. Cointelegraph publicly acknowledged the compromise and advised users not to interact with pop-ups promoting CTG tokens or CoinTelegraph ICO airdrops, and warned against connecting wallets to suspicious prompts. The full financial losses from this specific Cointelegraph incident were not separately disclosed; however, a nearly simultaneous Inferno Drainer-linked attack against CoinMarketCap two days prior resulted in approximately $43,266 stolen from over 110 users in under 30 minutes. Both sites were cleaned promptly and the companies stated they strengthened security controls following the incidents.","heading":"June 2025 Banner Advertising System Compromise (Inferno Drainer)","sources":[],"severity":"medium"},{"content":"Blockchain investigator ZachXBT played a central role in alerting the crypto community to the January 2024 MailerLite phishing campaign. Via his Telegram channel on January 23, 2024, ZachXBT identified a specific multichain wallet address (0xe7D13137923142A0424771E1778865b88752B3c7) as the attacker's primary receiving address, noting it had accumulated over $580,000 within hours of the campaign launching, with approximately 80 transactions on Ethereum alone. ZachXBT's early warning enabled Blockaid and other security infrastructure providers to block malicious transactions in real time, with Blockaid reporting it safeguarded an additional $2.7 million in user funds that would otherwise have been drained. The attacker's transaction records were later analyzed and confirmed by multiple on-chain analytics firms to be consistent with Angel Drainer Group infrastructure, establishing the drainer attribution.","heading":"ZachXBT Investigation and On-Chain Attribution","sources":[],"severity":"medium"},{"content":"Cointelegraph, founded in 2013, is one of the most widely read cryptocurrency and blockchain news publications globally. The incidents described in this profile represent attacks on Cointelegraph's third-party infrastructure and advertising systems rather than editorial or ownership misconduct. In both cases, Cointelegraph was a victim of supply-chain and platform compromises. Nevertheless, the incidents exposed Cointelegraph's subscribers and site visitors to significant financial risk on at least two separate occasions, raising questions about the platform's diligence in vetting email service providers and advertising partners. Cointelegraph's own reporting covered both incidents, and the platform issued user safety warnings during the June 2025 banner compromise.","heading":"Cointelegraph's Status as a Legitimate Outlet","sources":[],"severity":"medium"}],"timeline":[{"date":"2024-01-23","event":"Attackers use compromised MailerLite access to send phishing emails from Cointelegraph, WalletConnect, Token Terminal, De.Fi, and Decrypt official email addresses. Phishing emails promote fake airdrops and deploy Angel Drainer via malicious dApps. ZachXBT warns on Telegram and identifies attacker wallet address 0xe7D13137923142A0424771E1778865b88752B3c7.","source":"","source_url":"https://crypto.news/cointelegraph-others-sent-phishing-emails-in-presumed-hack/"},{"date":"2024-01-23","event":"ZachXBT reports over $580,000 has been drained from victims across multiple chains within hours of the campaign launch.","source":"","source_url":"https://decrypt.co/214033/hackers-target-crypto-email-lists-send-phishing-attacks-steal-700000"},{"date":"2024-01-24","event":"MailerLite confirms the breach, disclosing that a support team member was socially engineered via a fraudulent Google sign-in page. 117 accounts were initially reported as accessed (later revised to 70), with four used to launch phishing campaigns. MailerLite notified affected customers within 8 hours.","source":"","source_url":"https://www.mailerlite.com/newsroom/securityincidentnotice"},{"date":"2024-01-24","event":"Total losses from the MailerLite phishing campaign estimated at approximately $700,000 in liquid assets (Nansen's $3.3M figure revised downward after accounting for illiquid XBANKING tokens). Blockaid reports it protected an additional $2.7 million in user funds.","source":"","source_url":"https://decrypt.co/214033/hackers-target-crypto-email-lists-send-phishing-attacks-steal-700000"},{"date":"2025-06-21","event":"Cointelegraph's banner publishing system is briefly compromised. A malicious JavaScript payload is injected via a fraudulent ad network domain resembling AdButler, displaying a fake CTG token ICO airdrop pop-up connected to Inferno Drainer infrastructure.","source":"","source_url":"https://cryptoslate.com/cointelegraph-and-coinmarketcap-front-ends-compromised-with-scam-links-over-the-weekend/"},{"date":"2025-06-22","event":"Cointelegraph publicly warns users not to interact with pop-ups promoting CTG tokens or connect wallets to suspicious prompts. The compromised banner system is cleaned. Help Net Security and Scam Sniffer attribute both the Cointelegraph and CoinMarketCap attacks to Inferno Drainer customers.","source":"","source_url":"https://www.helpnetsecurity.com/2025/06/23/coinmarketcap-cointelegraph-compromised-to-serve-pop-ups-to-drain-crypto-wallets/"}],"sources_used":[],"source_tags":["zachxbt"],"addresses":[],"reviewed":true,"reviewed_by":null,"model_used":"claude-sonnet","created_at":"2026-05-04T16:05:04.221027+00:00","updated_at":"2026-08-29T01:35:52.552+00:00"}}