Gelalens

Market Prices

Coin Price 24h
BTC Bitcoin
$75,691.4 -1.18%
ETH Ethereum
$2,395.66 -2.42%
SOL Solana
$97.1 -3.24%
BNB BNB Chain
$711.8 -0.86%
XRP XRP Ledger
$1.27 -10.06%
DOGE Dogecoin
$0.0792 -4.14%
ADA Cardano
$0.1925 -5.96%
AVAX Avalanche
$7.26 -3.62%
DOT Polkadot
$0.9745 -1.38%
LINK Chainlink
$10.71 -5.94%

Fear & Greed

51

Neutral

Market Sentiment

Event Calendar

{{年份}}
10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

12
05
halving BCH Halving

Block reward halving event

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

18
03
unlock Sui Token Unlock

Team and early investor shares released

28
03
unlock Arbitrum Token Unlock

92 million ARB released

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

Altseason Index

42

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$75,691.4
1
Ethereum
ETH
$2,395.66
1
Solana
SOL
$97.1
1
BNB Chain
BNB
$711.8
1
XRP Ledger
XRP
$1.27
1
Dogecoin
DOGE
$0.0792
1
Cardano
ADA
$0.1925
1
Avalanche
AVAX
$7.26
1
Polkadot
DOT
$0.9745
1
Chainlink
LINK
$10.71

🐋 Whale Tracker

🔴
0x8f2c...fe7e
1d ago
Out
325,890 USDC
🔵
0x1f58...6441
6h ago
Stake
1,356,588 USDT
🔵
0xf93a...aafa
3h ago
Stake
31,420 BNB

💡 Smart Money

0x1ae6...0f6c
Top DeFi Miner
+$1.5M
70%
0x44b2...f53d
Top DeFi Miner
+$0.6M
94%
0xe2b3...c50a
Early Investor
+$2.2M
80%

🧮 Tools

All →
Cryptopedia

The WordPress Backdoor: How 2,000 Hacked Sites Are Draining Crypto Wallets

0xWoo
You paste a CAPTCHA code into PowerShell. That’s all it takes. Your wallet’s recovery phrase is now on a C2 server in Eastern Europe, and your assets will be swept within minutes. This isn’t a hypothetical. Check Point Research just exposed a campaign that has compromised nearly 2,000 WordPress sites since May, using fake CAPTCHA prompts to deploy ransomware and steal crypto wallet recovery phrases. The attack is still active as of July 24. Mentorship is scarce; self-education is mandatory. Here’s the context. The attackers don’t need a zero-day. They exploit common WordPress plugin vulnerabilities, plant malicious code, and turn those sites into command-and-control hubs. When a visitor hits one of these sites, they see a fake CAPTCHA challenge. The instructions: press Win+R, type “powershell”, and paste the provided code. That code downloads a payload that steals browser cookies, screenshots, and—most critically—cryptocurrency wallet recovery phrases stored in files or clipboard. The malware then spreads via network shares and USB drives. The scale is staggering: 31,000+ screenshots, 700+ compressed archives of stolen data, and over 6,000 distinct IP addresses infected. This is not a script kiddie operation. This is a mature, automated pipeline designed to harvest your private keys. Let’s talk about the core mechanics. The attackers specifically target recovery phrases. They know that any wallet seed exposed on a machine is game over. The malware scrapes file paths, searches for common phrase patterns (12 or 24 words), and exfiltrates them to the C2. Once the attacker has your seed, they can import your wallet on any device, drain everything, and move funds through mixers or privacy coins. No smart contract vulnerability, no DeFi exploit—just a simple social engineering trick that bypasses all the cryptography you trust. From my own experience auditing trading firms, I’ve seen senior quants lose six-figure portfolios because they stored a seed phrase in a text file on their trading laptop. The human factor is the weakest link, and here it’s being exploited with surgical precision. Here’s the contrarian angle. The crypto community obsesses over smart contract audits, MEV protection, and cross-chain bridges. But the most dangerous vulnerability sits on your desktop. Retail investors spend hours comparing APYs and gas fees, yet they’ll blindly paste PowerShell commands from a website. That’s the gap between institutional reality and retail behavior. Institutions enforce endpoint security—no admin rights, no unauthorized scripts, hardware wallets only. Retail thinks “it won’t happen to me.” Liquidity dries up when everyone is looking away. In this case, the liquidity is your personal wallet balance, and it’s being siphoned off by a CAPTCHA. Takeaway: Stop trusting your machine. If you use a software wallet on a computer that has ever visited a sketchy site, your seed might already be compromised. The only safe approach is a hardware wallet with a physically stored recovery phrase, and never—ever—paste commands into a terminal you don’t fully understand. The attackers are iterating. They’ll find new ways to trick you. Your job is to make their job harder. Data doesn’t care about your feelings. Protect your keys, or someone else will. Mentorship is scarce; self-education is mandatory. Liquidity dries up when everyone is looking away. The chart is lying to you—look at the volume delta.