Skip to main content
AVOID.NET

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·3hUFLy…ysn1

Summary

Cointelegraph is a major legitimate cryptocurrency news outlet that has been a victim of two distinct infrastructure compromises. In January 2024, attackers breached its email service provider MailerLite and sent phishing emails to subscribers using Angel Drainer malware, resulting in estimated losses of $580,000 to over $700,000 across affected platforms. In June 2025, attackers separately compromised Cointelegraph's banner advertising system to serve Inferno Drainer-linked pop-ups promoting a fake CTG token airdrop to site visitors.

Connected Entities

4 entities · 60 linked investigations
Organizations
Tokens
Cointelegraph
Relationships
  • Inferno Drainermentioned withEthereum(70%)
  • Inferno Drainermentioned withZachXBT(65%)
  • Cointelegraphmentioned withEthereum(60%)
  • Cointelegraphmentioned withInferno Drainer(80%)
  • Cointelegraphmentioned withZachXBT(70%)
  • ZachXBTmentioned withEthereum(70%)
Have evidence about Cointelegraph?

Timeline(6 events)

23 January 2024

Attackers use compromised MailerLite access to send phishing emails from Cointelegraph, WalletConnect, Token Terminal, De.Fi, and Decrypt official email addresses. Phishing emails promote fake airdrops and deploy Angel Drainer via malicious dApps. ZachXBT warns on Telegram and identifies attacker wallet address 0xe7D13137923142A0424771E1778865b88752B3c7.

23 January 2024

ZachXBT reports over $580,000 has been drained from victims across multiple chains within hours of the campaign launch.

24 January 2024

MailerLite confirms the breach, disclosing that a support team member was socially engineered via a fraudulent Google sign-in page. 117 accounts were initially reported as accessed (later revised to 70), with four used to launch phishing campaigns. MailerLite notified affected customers within 8 hours.

24 January 2024

Total losses from the MailerLite phishing campaign estimated at approximately $700,000 in liquid assets (Nansen's $3.3M figure revised downward after accounting for illiquid XBANKING tokens). Blockaid reports it protected an additional $2.7 million in user funds.

21 June 2025

Cointelegraph's banner publishing system is briefly compromised. A malicious JavaScript payload is injected via a fraudulent ad network domain resembling AdButler, displaying a fake CTG token ICO airdrop pop-up connected to Inferno Drainer infrastructure.

22 June 2025

Cointelegraph publicly warns users not to interact with pop-ups promoting CTG tokens or connect wallets to suspicious prompts. The compromised banner system is cleaned. Help Net Security and Scam Sniffer attribute both the Cointelegraph and CoinMarketCap attacks to Inferno Drainer customers.

Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events).

model: claude-sonnet

generated: 5/4/2026, 4:05:04 PM

last updated: 8/29/2026, 1:35:52 AM

6 views

avoid.net — verified advice for a post-truth world