Hackers Briefly Compromise CoinMarketCap’s Homepage – Is It Safe Now?
The CoinMarketCap exploit was traced to a compromised third-party script embedded in a doodle image on its homepage, which triggered unauthorized code tha prompted users to verify their crypto wallets.
Crypto data provider CoinMarketCap has recovered from a brief security lapse. The incident exposed website visitors to a deceptive pop-up urging them to connect their crypto wallets.
The June 20 incident disrupted the platform’s front-end interface for a few hours before the team took corrective action.
CoinMarketCap’s Breach Traced to Malicious Doodle
According to the company, the breach involved an unexpected pop-up on its homepage, instructing users to verify their wallets to access full account features.
“We’re aware that a malicious pop-up prompting users to ‘Verify Wallet’ has appeared on our site. Do NOT connect your wallet,” the data aggregator warned.
While the message mimicked legitimate functionality, security analysts quickly warned that the request was malicious and likely intended to compromise user wallets.
The Malicious Pop-Up Message on CoinMarketCap Homepage. Source:
X/Jameson Lopp
In a follow-up update, CoinMarketCap revealed that the issue stemmed from a doodle image embedded on its homepage. The image was linked to an external call that triggered unauthorized JavaScript, resulting in the suspicious wallet prompt.
“On June 20, 2025, our security team identified a vulnerability related to a doodle image displayed on our homepage. This doodle image contained a link that triggered malicious code through an API call, resulting in an unexpected pop-up for some users when visited our homepage,” CoinMarketCap explained.
Investigators found that the breach may have originated from a compromised third-party service, likely an ad network. This service injected malicious code into the platform’s display system.
Meanwhile, CoinMarketCap clarified that external dependencies used to serve content—not its internal infrastructure—caused the issue.
The platform confirmed that all affected scripts and assets had been removed, and new safeguards were introduced to prevent similar exploits. It also assured users that the situation was under control and that visiting the site is now safe.
“We’re actively monitoring user feedback and our support team is standing by to ensure all inquiries are promptly addressed. We are committed to maintaining the highest standards of security and transparency, and we thank you for the continued trust of our community,” it added.
CoinMarketCap, owned by Binance, continues to serve millions of users who track real-time crypto prices and market data.
However, this episode reminds us that even the most established platforms must remain proactive in protecting users from increasing threats.
Due to this, security experts have urged crypto wallet users to always take precautions by constantly reviewing recent activity and avoiding connecting to unknown dApps or prompts.
So far this year, hackers have aggressively targeted vulnerabilities across even the most reputable platforms. Combined, these breaches have led to over $2 billion in stolen assets, including a massive $1.4 billion exploit on Bybit.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Mars Morning News | Ethereum Fusaka upgrade officially activated; ETH surpasses $3,200
The Ethereum Fusaka upgrade has been activated, enhancing L2 transaction capabilities and reducing fees; BlackRock predicts accelerated institutional adoption of cryptocurrencies; cryptocurrency ETF inflows have reached a 7-week high; Trump nominates crypto-friendly regulatory officials; Malaysia cracks down on illegal Bitcoin mining. Summary generated by Mars AI. The accuracy and completeness of this summary are still undergoing iterative updates.

Do you think stop-losses can save you? Taleb exposes the biggest misconception: all risks are packed into a single blow-up point.
Nassim Nicholas Taleb's latest paper, "Trading With a Stop," challenges traditional views on stop-loss orders, arguing that stop-losses do not reduce risk but instead compress and concentrate risk into fragile breaking points, altering market behavior patterns. Summary generated by Mars AI. The accuracy and completeness of this summary are still being iteratively improved by the Mars AI model.

With capital outflows from crypto ETFs, can issuers like BlackRock still make good profits?
BlackRock's crypto ETF fee revenue has dropped by 38%, and its ETF business is struggling to escape the cyclical curse of the market.

Incubator MEETLabs today launched the large-scale 3D fishing blockchain game "DeFishing". As the first blockchain game on the GamingFi platform, it implements a dual-token P2E system with the IDOL token and the platform token GFT.
MEETLabs is an innovative lab focused on blockchain technology and the cryptocurrency sector, and also serves as the incubator for MEET48.

