Summary
MyAlgo was a non-custodial web browser wallet for the Algorand blockchain, developed by Rand Labs. Between January and March 2023, a supply-chain attack via a compromised CDN (content delivery network) resulted in the theft of approximately $9.6 million in ALGO and USDC across at least five distinct attack waves. The wallet was officially shut down on January 30, 2024, following the incident and subsequent user attrition.
Connected Entities
1 entities- + 3 more
Timeline(13 events)
2021-02-16
Rand Labs releases updated MyAlgo wallet with multisig support, establishing it as a primary Algorand wallet.
GlobeNewswire2023-01-21
Malicious JavaScript worker uploaded to the CDN serving wallet.myalgo.com, beginning silent private key exfiltration from users who unlocked their wallets.
Quadriga Initiative case study2023-02-19
First wave of active thefts begins; attackers use harvested credentials to drain approximately $7.2 million confirmed across 17 addresses.
D13.co preliminary advisory report2023-02-21
First theft wave concludes. Total losses in this wave estimated at $9.2-9.6 million including 19.5M ALGO and 3.5M USDC. ZachXBT publicly quantifies stolen amounts.
CoinDesk2023-02-27
MyAlgo issues public warning advising all mnemonic wallet users to immediately withdraw funds. New wallet version released, ending the CDN injection.
Decrypt2023-02-28
CoinDesk publishes initial reporting. ChangeNOW freezes approximately $1.5 million in stolen funds transiting through its platform.
CoinDesk2023-03-05
Second wave of thefts begins, targeting additional compromised credentials.
D13.co fifth wave data2023-03-06
Algorand Foundation publicly acknowledges the exploit after approximately two weeks of silence. Algodex also reports its company wallet was infiltrated by a malicious actor (loss under $55,000). Lofty.ai reports $65,000 theft on Algorand.
CoinTelegraph2023-03-09
Algorand Foundation CTO John Woods releases statement confirming the exploit is not caused by an underlying issue with the Algorand protocol or SDK.
Blockhead2023-04-01
Exploit details — including the CDN injection date of January 21 — are publicly revealed. MyAlgo discloses preliminary findings identifying CDN MITM as the attack vector.
Quadriga Initiative case study2024-01-30
MyAlgo wallet officially shut down and decommissioned. Platform no longer accessible for transaction signing.
Bitget Wallet guideDecision Log
- hash: D2qQi3gakPoV8fEB78TtLaEfyY2g4Lh4yYZzuZ8PViuf
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:43 AM
last updated: 5/28/2026, 4:12:45 PM
avoid.net — verified advice for a post-truth world