BeChain

Market Prices

BTC Bitcoin
$79,956.8 -0.05%
ETH Ethereum
$2,497.13 +0.78%
SOL Solana
$106.45 +2.41%
BNB BNB Chain
$749.3 -3.69%
XRP XRP Ledger
$1.41 -0.45%
DOGE Dogecoin
$0.0895 -3.39%
ADA Cardano
$0.2194 -0.68%
AVAX Avalanche
$7.64 +0.37%
DOT Polkadot
$0.9639 +5.88%
LINK Chainlink
$12.39 +2.85%

Event Calendar

{{年份}}
15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

28
03
unlock Arbitrum Token Unlock

92 million ARB released

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

18
03
unlock Sui Token Unlock

Team and early investor shares released

12
05
halving BCH Halving

Block reward halving event

Tools

All →

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$79,956.8
1
Ethereum ETH
$2,497.13
1
Solana SOL
$106.45
1
BNB Chain BNB
$749.3
1
XRP Ledger XRP
$1.41
1
Dogecoin DOGE
$0.0895
1
Cardano ADA
$0.2194
1
Avalanche AVAX
$7.64
1
Polkadot DOT
$0.9639
1
Chainlink LINK
$12.39

🐋 Whale Tracker

🔴
0xe747...6b94
3h ago
Out
3,152,680 USDC
🟢
0x2f5e...8f05
30m ago
In
2,442,109 USDC
🔵
0x7e78...e691
2m ago
Stake
50,056 BNB
Video

WordPress Honeypot: How a Fake CAPTCHA Campaign Is Draining Crypto Wallets

CryptoEagle
A sophisticated cyberattack campaign dubbed "StopAndProtect" has been quietly siphoning cryptocurrency wallet recovery phrases from unsuspecting users since May 2024, leveraging compromised WordPress sites as command-and-control hubs. According to a detailed report from Check Point Research, the attack has infected over 6,000 IP addresses, compromised nearly 2,000 WordPress websites, and collected more than 31,000 screenshots and 700 compressed archives of stolen data. The attack is still active as of July 24, 2024, indicating a mature and ongoing threat to crypto holders. The attack chain is deceptively simple yet highly effective. Victims are directed to a compromised WordPress site that displays a fake CAPTCHA verification page. Instead of a standard image puzzle, the page instructs Windows users to copy and paste a malicious PowerShell command into their terminal. The command executes a series of actions: it downloads and runs a remote access trojan (RAT), steals browser credentials and cryptocurrency wallet recovery phrases, then deploys a ransomware payload that encrypts files and demands a ransom. The same malware also spreads through local network shares and USB drives, amplifying the infection. What makes this attack particularly dangerous is its targeting of crypto wallet recovery phrases—the 12 or 24-word seed that grants full control over a wallet. Once obtained, attackers can drain all funds without needing to crack passwords or bypass two-factor authentication. The report notes that the attackers likely automate the process of checking wallet balances and transferring assets, making the theft instantaneous and irreversible. "Hype dies. Data breathes," said Liam Smith, a copy trading community founder and former economic analyst. Smith, who has tracked over a dozen similar campaigns, emphasized that the attack exploits a fundamental trust gap: users are conditioned to solve CAPTCHAs without questioning the underlying code. "Your emotion is not my edge. The attackers are not using zero-day exploits; they're exploiting human obedience to instructions. That's harder to patch than any software bug." From a technical perspective, the campaign demonstrates a high degree of operational maturity. The compromised WordPress sites are not just malware hosts—they also serve as C2 servers, storage for exfiltrated data, and distribution points for updated payloads. The attackers have managed to maintain control over hundreds of infected machines, indicating a well-resourced team or a sophisticated botnet. The geographic distribution of infected IPs shows the United States, Russia, and India as primary targets, but the attack is global in scope. Check Point researchers were able to collect a massive dataset by deploying honeypots and reverse-engineering the malware. They found that the ransomware component, named "StopAndProtect," is a variant of earlier ransomware strains but with added features for credential theft. The malware also includes a keylogger that captures clipboard data, which is a direct threat to users who copy-paste wallet addresses during transactions. "Don't buy the noise. Buy the node," Smith added, referring to the need for systemic security rather than reactive panic. "This attack is a textbook example of why storing recovery phrases digitally is a single point of failure. The node is the hardware wallet; the noise is the clickbait warning you to 'update your security settings.'" The campaign's longevity is concerning. Starting in May and still active in late July, it has evolved through multiple iterations. The researchers observed that the fake CAPTCHA pages occasionally change their appearance, and the PowerShell commands are obfuscated to evade detection. This suggests the attackers are actively monitoring detection methods and adjusting their tactics. For the wider crypto ecosystem, the attack highlights a persistent vulnerability: the human layer. Even the most secure smart contract or DeFi protocol is useless if a user's private key is stolen from an infected computer. The report urges users to adopt a strict policy of never entering recovery phrases into any website, application, or command line interface. Hardware wallets that keep private keys offline remain the gold standard. WordPress site administrators are also on the front line. The attack likely exploits known vulnerabilities in outdated plugins or themes. With nearly 2,000 sites compromised, the campaign underscores the importance of regular updates, security audits, and the use of web application firewalls. Smith noted, "Simplicity scales. Complexity collapses. If you run a WordPress site, simplify your plugin stack. Fewer plugins mean fewer attack surfaces." Law enforcement agencies in multiple jurisdictions may be investigating, but the anonymous nature of cryptocurrency and the use of VPNs and mixers make attribution difficult. The stolen funds are likely laundered through privacy coins or decentralized exchanges, leaving victims with little recourse. As the crypto market grinds through a bear cycle, survival matters more than gains. This attack is a stark reminder that the safest strategy is not chasing alpha but protecting existing capital. The data is clear: over 31,000 screenshots captured, 700 archives exfiltrated, and likely thousands of wallets drained. The question is not whether this will happen again, but whether the next iteration will be more sophisticated. "Simplicity scales. Complexity collapses," Smith concluded. "The attackers keep it simple: fake CAPTCHA, one command, instant theft. The defense must be equally simple: never type your seed phrase, never paste unknown code, and store your keys offline. Markets don't care about your caution, but they will punish your carelessness."

WordPress Honeypot: How a Fake CAPTCHA Campaign Is Draining Crypto Wallets

WordPress Honeypot: How a Fake CAPTCHA Campaign Is Draining Crypto Wallets

WordPress Honeypot: How a Fake CAPTCHA Campaign Is Draining Crypto Wallets

Fear & Greed

73

Greed

Market Sentiment

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0x121f...37c7
Market Maker
-$1.0M
86%
0x2827...16b9
Institutional Custody
+$1.1M
80%
0x9ce6...f891
Institutional Custody
+$4.5M
90%