Hook
Nearly 2,000 WordPress sites turned into silent predators. Not for traffic, not for SEO—but to steal your crypto wallet recovery phrase. This isn't a hypothetical. Since May 2024, a campaign dubbed StopAndProtect has compromised over 6,000 IPs, amassed 31,000+ screenshots, and 700+ compressed archives. The attack chain is elegant, brutal, and entirely avoidable. The pool remembers what the ticker forgets.
Context
Check Point Research published the breakdown this week. The attack vector: compromised WordPress sites acting as command-and-control nodes. Attackers inject fake CAPTCHA prompts that trick Windows users into pasting a PowerShell command. One click, and the malware spreads—through the network, through USB drives. It exfiltrates browser cookies, credentials, and—crucially—cryptocurrency wallet recovery phrases. Then it deploys a ransomware payload. The operators are methodical. They screenshot active windows, compress stolen data, and monitor victims in real time. The campaign is still active as of July 24.
This is not a sophisticated zero-day exploit. It's a social engineering chain built on trust in a CAPTCHA—a mechanism designed to prove you're human. It works because users are conditioned to comply. The code is simple. The execution is terrifying.
Core: The Technical Breakdown
Let me walk through the infection chain, because the details matter if you want to survive.
- Infection Entry: Attackers compromise WordPress sites, likely through outdated plugins or themes. Based on my experience auditing ICO whitelists in 2017, I've seen how easily a misconfigured upload function can become a backdoor. The attackers weaponize the site itself—hosting malware payloads, storing exfiltrated data, and issuing commands.
- The Fake CAPTCHA: A visitor lands on a compromised site. A pop-up appears: "Please verify you are human." It looks legitimate. But instead of a simple checkbox, the user is instructed to press
Windows + R, paste a command, and hit Enter. The command spawns a PowerShell script that downloads the first-stage payload. This is the critical moment. Code is law, but audits are mercy—and there's no audit when the user is the one executing the command.
- Persistence and Propagation: The malware installs a backdoor, then spreads via network shares and removable USB drives. It enumerates files, screenshots active windows, and looks for any file containing "recovery", "seed", "wallet", or "private key". The attackers don't just steal your seed phrase—they steal your entire digital identity.
- Data Exfiltration: Stolen files are compressed and sent to the compromised WordPress site, which acts as a staging server. Over 31,000 screenshots and 700+ compressed archives were collected. That's not a small operation. That's a factory.
- Ransomware: Finally, the machine is encrypted, and a ransom note demands payment in cryptocurrency. The victim is left with a choice: pay or lose their data. But the seed phrase is already gone. The wallet is drained before the ransom note even appears.
Based on my 2020 Uniswap v2 analysis, where I reverse-engineered bonding curves to expose MEV extraction, I can tell you this: the attack chain is optimized for speed. The screenshot collection suggests the attacker is manually reviewing victim screens for active wallets. They're not just automating—they're hunting.
Contrarian: The Real Threat Is Not the Ransomware
Most headlines focus on the ransomware component. But the ransomware is a distraction. The real prize is the recovery phrase. The attackers don't care about encrypting your files—they care about emptying your cold wallet, your hot wallet, your MetaMask, your Ledger Live cache. Ransomware is just the cover story.
Here's the contrarian angle: This attack reveals a fundamental flaw in how we secure non-custodial wallets. The security community obsesses over smart contract vulnerabilities, over DAO governance attacks, over Layer 2 fragmentation. But the weakest link has always been the human operating system. A user who types their seed phrase into a website—even a fake CAPTCHA—is not protected by any audit, any multisig, any time-lock. Speculation is just data with a heartbeat—but that heartbeat stops when the seed phrase is captured.
And the WordPress ecosystem? It's a vector we've ignored for too long. There are dozens of Layer 2s slicing liquidity, but the same WordPress plugins are powering millions of sites—and many of them are unpatched. This campaign proves that the attack surface is not just the blockchain; it's the internet infrastructure that connects to it.
Takeaway
The next time you see a CAPTCHA, pause. Ask yourself: Is this site asking me to execute code? If yes, close the tab. Entropy increases until someone audits it—and today, that someone is you. The market is euphoric, but the predators are quiet. They're not attacking the chain; they're attacking the chair. Protect your seed phrase like it's the only key to a vault, because it is. The pool remembers what the ticker forgets—and the pool remembers every seed phrase it ever saw.