IntegraChain

Market Prices

BTC Bitcoin
$79,588.2 -1.82%
ETH Ethereum
$2,454.07 -2.60%
SOL Solana
$102.27 -1.58%
BNB BNB Chain
$746.6 +4.04%
XRP XRP Ledger
$1.4 -3.33%
DOGE Dogecoin
$0.0856 -1.87%
ADA Cardano
$0.2127 -3.71%
AVAX Avalanche
$7.47 -0.45%
DOT Polkadot
$0.8988 +2.83%
LINK Chainlink
$11.73 -2.06%

Event Calendar

{{年份}}
22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

12
05
halving BCH Halving

Block reward halving event

18
03
unlock Sui Token Unlock

Team and early investor shares released

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

28
03
unlock Arbitrum Token Unlock

92 million ARB released

Tools

All →

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$79,588.2
1
Ethereum ETH
$2,454.07
1
Solana SOL
$102.27
1
BNB Chain BNB
$746.6
1
XRP Ledger XRP
$1.4
1
Dogecoin DOGE
$0.0856
1
Cardano ADA
$0.2127
1
Avalanche AVAX
$7.47
1
Polkadot DOT
$0.8988
1
Chainlink LINK
$11.73

🐋 Whale Tracker

🔵
0x56a4...8a7a
30m ago
Stake
13,972 BNB
🟢
0x960a...6d18
30m ago
In
6,849,361 DOGE
🟢
0xf4e2...7750
12h ago
In
4,614 ETH
DAO

StopAndProtect Ransomware Campaign Hijacked WordPress Sites to Harvest Crypto Recovery Phrases

BenLion
The first anomaly was not a token price move or a smart contract exploit. It was a fake CAPTCHA. Users were told to copy a command into PowerShell. They pasted it. Their Windows machines then handed over credentials, files, and, in the most damaging cases, cryptocurrency wallet recovery phrases. That is the central finding from Check Point Research on the StopAndProtect ransomware operation: the attack did not rely on a novel blockchain protocol flaw. It relied on ordinary users trusting a page that asked for one more step before access. Hashes do not lie, but wallets do. This campaign is a reminder that custody risk often begins outside the ledger. The reported campaign used a large web infrastructure as both delivery mechanism and command layer. Check Point identified roughly 1,900 compromised WordPress sites involved in malware hosting, data theft, and ransomware deployment. The group continued operating from May into at least late July, and the campaign had reached more than 6,000 IP addresses by July 24. Researchers collected more than 31,000 screenshots and more than 700 compressed data packages linked to the operation. Those numbers matter because they show a mature, repeated workflow rather than a one-off hack. The operation followed a complete chain: initial compromise, victim luring, local execution, data collection, network or USB propagation, and ransomware deployment. The immediate vector was a fake verification page. Windows users encountered a page that looked like a normal security check. It asked them to run a PowerShell command. Once executed, the malware began stealing credentials and searching for cryptocurrency wallet material. That detail is important. The attack does not pretend to be a wallet application at first. It does not claim to sign a transaction. It borrows the user’s trust in browser-based security prompts. In that sense, the attack resembles social engineering more than DeFi hacking. But the payout is still on-chain. If the attacker recovers a valid seed phrase, they can reconstruct the wallet and move assets without touching the original software. WordPress appears in this case as critical infrastructure for the attackers, not as a blockchain protocol. The compromised sites were used to host malicious code, send commands, and store stolen files. That makes the CMS ecosystem a force multiplier. A single weak website can become a staging point for a much larger operation. Based on my audit experience, large-scale web compromises usually start from common failure modes: outdated plugins, unpatched themes, weak administrative credentials, and poor monitoring. The campaign does not need a zero-day vulnerability to succeed. It only needs enough footholds to keep the malware distribution layer alive. The data collection side also suggests automation. Thirty-one thousand screenshots is not a manual collection job. It points to remote monitoring, repeated victim capture, and structured triage. The malware likely ran across infected endpoints, captured desktop activity or file system state, and pushed compressed bundles back to attacker-controlled infrastructure. From a forensic perspective, that pattern means the attackers were not waiting for a single high-value payout. They were harvesting broadly. In crypto cases, that matters because attackers can script seed phrase validation across chains, scan for balances, and drain wallets faster than most users can react. The ledger does not care whether the key was stolen from a phishing page or a compromised desktop. It only verifies signatures. The most serious victim profile is not the sophisticated trader or the DeFi power user. It is the ordinary holder who keeps a recovery phrase on a computer, in a document, in a screenshot, or in an application that appears to need it. A seed phrase should never be entered into a webpage. It should never be copied into a terminal prompt. It should not live on a device connected to the internet unless that device is air-gapped from the rest of the operating system and handled with extreme discipline. The cleanest defense remains a hardware wallet and an offline physical backup. That is not a luxury recommendation. It is a custody control. For WordPress operators, the signal is also direct. This campaign shows why a neglected CMS is not a harmless web presence. If a site is used as a malware host, it becomes part of the attack surface for every visitor it reaches. Site owners should update core software, plugins, and themes immediately. They should rotate credentials, review file changes, enable two-factor authentication, and monitor for unexpected scripts or outbound connections. Security is not a once-a-year maintenance task. In a campaign like this, every unpatched site is an additional relay. The market reaction to this kind of event is usually underweighted. Prices do not move much because no token contract is broken and no exchange is hacked. That creates a false sense of calm. The risk is individualized. One victim may lose their entire wallet. A thousand victims may lose uncorrelated balances. The market can look stable while custody losses continue quietly. That is why this event is neutral for token valuation but negative for user trust. It is a slow drag on confidence, especially for new users who assume crypto custody is protected by the same guarantees as a bank account. There is also a secondary industry effect. The campaign benefits security vendors, threat-intelligence teams, endpoint-detection tools, and hardware wallet providers. When attackers prove that seed phrase theft is profitable, demand shifts toward stronger custody controls. That is not speculative optimism. It is an obvious chain reaction. Follow the liquidity, not the narrative. In this case, follow the threat: the flow of stolen keys is heading toward tools that can prevent exposure, detect infection, and preserve assets. Security demand often follows incidents rather than precedes them. The contrarian angle is that the attack may look less impressive than it is. A fake CAPTCHA is not cutting-edge exploit engineering. It is a mature method because it works. The sophistication is not in the cryptography. It is in scale, persistence, and the way the attackers chained web compromise with endpoint theft. The campaign is also a warning against over-indexing on smart contract audits. Audits are necessary, but they do not protect a user whose recovery phrase has already been copied into a malicious script. A protocol can be secure and a wallet can still be empty. Another blind spot is the assumption that crypto theft requires blockchain-specific malware. This campaign proves the opposite. The malware may be designed for ransomware and general credential theft, yet it remains highly relevant to crypto custody. Attackers search for wallet files and seed phrases because those files are liquid. Once converted into private keys, they can be exchanged for usable balances across chains. Fragmented yields, fragmented trust. The same fragmentation applies to security. Assets are split across wallets, chains, devices, and browsers, and every exposed device becomes a possible leak. A practical pre-mortem is simple. If an attacker reaches your Windows machine and can get you to run a command, the rest is procedural. The command can collect credentials. It can search the file system. It can record activity. It can copy wallet-related files. It can propagate to USB drives and local networks. If a seed phrase is present, the attacker does not need a smart contract vulnerability. They already have the key. On-chain truth is greater than Twitter narrative, but it is also colder than users expect. The chain will happily process a valid withdrawal signed by a stolen key. The forward signal for next week is not a price question. It is an operational one. Watch whether new variants of the same fake-CAPTCHA-to-PowerShell pattern appear on other platforms. Watch whether the count of compromised WordPress sites continues rising. Watch whether wallet vendors, security researchers, and browsers publish stronger warnings against pasting commands into terminal windows. Watch whether hardware wallet adoption rises among retail users after exposure to these reports. The market may not move, but the threat surface will. The lesson is straightforward. Bull market euphoria masks weak custody habits. Users focus on allocation, yield, and entry price while leaving their keys in insecure places. This StopAndProtect campaign does not attack the blockchain. It attacks the user. And in crypto, that is often enough. The next question is not whether the ledger can be trusted. The next question is whether your recovery phrase ever touched a machine that should not have seen it.

Fear & Greed

73

Greed

Market Sentiment

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0x8c94...63ee
Arbitrage Bot
+$3.2M
77%
0x1ddd...6a70
Experienced On-chain Trader
+$1.6M
78%
0xc2cd...7062
Market Maker
-$1.1M
88%