Gelalens

Market Prices

Coin Price 24h
BTC Bitcoin
$75,983.3 -1.30%
ETH Ethereum
$2,404.06 -2.91%
SOL Solana
$97.34 -3.50%
BNB BNB Chain
$711.7 -0.95%
XRP XRP Ledger
$1.29 -7.97%
DOGE Dogecoin
$0.0799 -3.43%
ADA Cardano
$0.1945 -5.17%
AVAX Avalanche
$7.27 -3.49%
DOT Polkadot
$0.9585 -3.70%
LINK Chainlink
$10.81 -5.10%

Fear & Greed

51

Neutral

Market Sentiment

Event Calendar

{{年份}}
18
03
unlock Sui Token Unlock

Team and early investor shares released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

12
05
halving BCH Halving

Block reward halving event

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

28
03
unlock Arbitrum Token Unlock

92 million ARB released

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$75,983.3
1
Ethereum
ETH
$2,404.06
1
Solana
SOL
$97.34
1
BNB Chain
BNB
$711.7
1
XRP Ledger
XRP
$1.29
1
Dogecoin
DOGE
$0.0799
1
Cardano
ADA
$0.1945
1
Avalanche
AVAX
$7.27
1
Polkadot
DOT
$0.9585
1
Chainlink
LINK
$10.81

🐋 Whale Tracker

🟢
0xb9be...050d
5m ago
In
3,797,480 USDT
🔵
0xbe2c...58d7
30m ago
Stake
1,540.66 BTC
🔵
0x0c6c...91e4
3h ago
Stake
9,913 SOL

💡 Smart Money

0x9f2d...6013
Experienced On-chain Trader
-$3.7M
66%
0xe830...0f36
Market Maker
+$3.3M
75%
0x6e81...79ec
Experienced On-chain Trader
+$2.8M
80%

🧮 Tools

All →
Gaming

The WordPress Vector: How 2,000 Compromised Sites Fuel a Crypto Recovery Phrase Heist

PrimePrime

The data is stark: 1,982 compromised WordPress domains, 6,000+ unique victim IPs, and over 31,000 screenshots captured from unsuspecting users. This is not a protocol exploit or a smart contract bug. It is a human-targeted attack chain that turns the most trusted element of crypto security—the recovery phrase—into a liability. Ledgers do not lie, only the narrative does. And the narrative here is that the weakest link in DeFi is still the user's desktop.

Context: The Attack Anatomy

Since May 2025, a threat actor known only as “StopAndProtect” has been running a sophisticated campaign that weaponizes WordPress websites as a global command-and-control infrastructure. The modus operandi is deceptively simple: visitors to a compromised site are greeted with a fake CAPTCHA prompt. Instead of verifying humanity, the prompt instructs Windows users to open PowerShell and paste a base64-encoded command. That single command downloads a multi-stage malware loader that exfiltrates browser cookies, credentials, and—most critically—cryptocurrency wallet recovery phrases from locally stored files. The same payload also deploys a ransomware component that encrypts documents and demands a crypto payment.

Based on my audit experience of over 200 DeFi protocols, I have seen countless smart contract vulnerabilities. But this attack is different—it does not exploit code; it exploits trust in visual interfaces. The fake CAPTCHA is a social engineering artifact that bypasses all technical defenses because the user voluntarily executes the malicious payload. The attackers have automated the entire lifecycle: compromise a WordPress site via outdated plugins, inject the malicious script, collect exfiltrated data in centralized storage servers, and then use the stolen recovery phrases to sweep wallet balances.

Core: The On-Chain Evidence Chain

Check Point Research, which tracked the campaign, documented over 31,000 unique screenshots stolen from victims. These screenshots are not random—they are deliberately captured from the desktop at moments when the wallet is open or when the recovery phrase is being typed. The attackers also collected 700+ compressed archives from infected machines, suggesting they are not only targeting crypto wallets but also any sensitive documents that could be leveraged for further extortion.

What makes this attack particularly dangerous for crypto holders is the irreversibility of the theft. Once a recovery phrase is captured, the attacker can generate the private keys offline, move funds to a fresh address, and then use a mixer or a privacy coin to obfuscate the trail. On-chain forensics can trace the flow, but the probability of recovery is near zero. The data shows that the average amount stolen per wallet is not disclosed, but given the scale of the compromise, the cumulative loss likely runs into the millions of dollars.

I have analyzed similar phishing campaigns in the past, but the scale here is unprecedented. The attackers do not need to exploit a zero-day vulnerability. They simply need a WordPress site with a vulnerable plugin—and there are hundreds of thousands of those. The campaign has been active since May, and as of late July, new infections were still being detected. This is not a one-off event; it is a sustained operation.

Contrarian Angle: Correlation Is Not Causation

Many in the security community will blame WordPress—and to some extent, they are right. WordPress powers over 40% of the web, and its plugin ecosystem is a constant source of vulnerabilities. However, the real vulnerability is not the CMS itself; it is the user's willingness to paste a command into PowerShell based on a visual prompt. The attack succeeds because humans have been conditioned to trust CAPTCHAs as a legitimate security measure. The attackers are exploiting a behavioral pattern, not a technical flaw.

Moreover, the crypto industry often focuses on protocol-level security—audits, formal verification, bug bounties—while ignoring the endpoint. A DeFi protocol can be mathematically sound, but if the user's machine is infected, the entire security model collapses. Survival is the ultimate alpha in a bear market, and in a bull market, euphoria masks technical flaws. Right now, the market is euphoric, and users are distracted by price action. They are not updating their WordPress plugins or questioning the legitimacy of a CAPTCHA.

Another counter-intuitive observation: the attackers are inadvertently helping security researchers. By collecting so many screenshots and compressed files, they have created a massive dataset for forensic analysis. The researchers were able to identify the attacker's own infrastructure because the malware inadvertently infected some of the attacker's test machines. This is a classic case of attackers being too aggressive in their own deployment.

Takeaway: The Next-Week Signal

The StopAndProtect campaign is a textbook example of how the intersection of legacy web vulnerabilities and crypto asset theft creates a new class of risk. The next evolution will likely target macOS and Linux users, or use more sophisticated lures such as fake browser update prompts. The on-chain signal to watch is a sudden spike in small-value transfers from dormant wallets to fresh addresses, which could indicate a mass sweep of stolen recovery phrases. Trust the math, ignore the hype—and never, ever paste a command into a terminal window that you did not personally write.

As I tell my clients: the strongest smart contract is worthless if the private key is typed into a compromised browser. Audit your own security habits before you audit a protocol.