<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>backend api vulnerability Archives - Coin Engineer</title>
	<atom:link href="https://coinengineer.net/blog/tag/backend-api-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>https://coinengineer.net/blog/tag/backend-api-vulnerability/</link>
	<description>Btc, Coins, Pre-Sale, DeFi, NFT</description>
	<lastBuildDate>Sat, 21 Jun 2025 06:56:58 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://coinengineer.net/blog/wp-content/uploads/2024/04/cropped-Coin-Engineer-Logo-Favicon-2-32x32.png</url>
	<title>backend api vulnerability Archives - Coin Engineer</title>
	<link>https://coinengineer.net/blog/tag/backend-api-vulnerability/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>CoinMarketCap Removed Malicious Code Threatening Crypto Wallets </title>
		<link>https://coinengineer.net/blog/coinmarketcap-removed-malicious-code-threatening-crypto-wallets/</link>
					<comments>https://coinengineer.net/blog/coinmarketcap-removed-malicious-code-threatening-crypto-wallets/#respond</comments>
		
		<dc:creator><![CDATA[Yeliz Akmaca]]></dc:creator>
		<pubDate>Sat, 21 Jun 2025 06:56:58 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[backend api vulnerability]]></category>
		<category><![CDATA[coinmarketcap hack news]]></category>
		<category><![CDATA[crypto api exploit]]></category>
		<category><![CDATA[crypto phishing threat]]></category>
		<category><![CDATA[doodles feature attack]]></category>
		<category><![CDATA[erc20 wallet scam]]></category>
		<category><![CDATA[fake wallet connection]]></category>
		<category><![CDATA[malicious javascript crypto]]></category>
		<category><![CDATA[metamask warning popup]]></category>
		<category><![CDATA[phantom wallet alert]]></category>
		<category><![CDATA[phishing in crypto sites]]></category>
		<category><![CDATA[wallet verification scam]]></category>
		<guid isPermaLink="false">https://coinengineer.net/blog/?p=44779</guid>

					<description><![CDATA[<p>The popular crypto tracking platform CoinMarketCap recently faced a significant security issue. When users accessed the site, they encountered a “Verify Wallet” pop-up on the screen. This message was a fake verification prompt asking users to connect their wallets. The platform quickly identified the attack and removed the malicious code from the system within three</p>
<p>The post <a href="https://coinengineer.net/blog/coinmarketcap-removed-malicious-code-threatening-crypto-wallets/">CoinMarketCap Removed Malicious Code Threatening Crypto Wallets </a> appeared first on <a href="https://coinengineer.net/blog">Coin Engineer</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><span data-c>The popular crypto tracking platform <strong>CoinMarketCap</strong> recently faced a significant security issue. When users accessed the site, they encountered a “Verify Wallet” <strong>pop-up</strong> on the screen. This message was a fake verification prompt asking users to connect their wallets. The platform quickly identified the attack and removed the malicious code from the system within three hours.</span><span data-ccp-props="{}"> </span></p>
<p><span data-c>Initially, users and community members reported the incident on social media. A user named <strong>“Jet”</strong> issued a warning on X. Soon after, MetaMask and Phantom wallets flagged <strong>CoinMarketCap</strong> as dangerous. Additionally, Phantom announced that “coinmarket.com was blocked.”</span><span data-ccp-props="{}"> </span></p>
<p><span data-c>Security firm Coinspect Security stated that the attack occurred through <strong>CoinMarketCap’s backend API</strong>. Malicious JavaScript codes were injected into the system via the platform’s ‘doodles’ feature. This technique could lead to wallets being drained without users’ knowledge. The pop-up requested <strong>ERC-20</strong> token approvals, aiming to scam users.</span><span data-ccp-props="{}"> </span></p>
<h2><span data-c>Rising Crypto Attacks Draw Attention</span><span data-ccp-props="{}"> </span></h2>
<p><span data-c>This incident brings other recent crypto attacks back into focus. In recent weeks,<a href="https://coinengineer.net/blog/israel-iran-tensions-weigh-on-markets-us-opens-lower/"> Iran-based</a> exchange <strong>Nobitex</strong> was targeted by Israeli hackers, causing over <strong>$100 million</strong> in damages. Around the same time, global giant Coinbase also faced a similar attack.</span><span data-ccp-props="{}"> </span></p>
<p><span data-c>CoinMarketCap had previously been hacked in October 2021, when around <strong>3.1 million users</strong>&#8216; email addresses were stolen. In this recent incident, a phishing attack aimed to gain access to users&#8217; private keys. The <strong>crypto community</strong> once again emphasized the importance of being cautious about prompts asking for wallet connections.</span><span data-ccp-props="{}"> </span></p>
<p><span data-c>CoinMarketCap announced that it has started working on improving security following the attack. Users must also act responsibly against such fake redirects. Avoiding untrusted links and regularly reviewing wallet access permissions are of vital importance.</span><span data-ccp-props="{}"> </span></p>
<p><span data-ccp-props="{}"> <em class="darkmysite_style_txt_border darkmysite_processed" data-darkmysite_alpha_bg="rgba(0, 0, 0, 0)">You can also freely share your thoughts and comments about the topic in the comment section. Additionally, don’t forget to follow us on our <a class="darkmysite_style_txt_border darkmysite_style_link darkmysite_processed" href="https://t.me/coinengineernews" target="_blank" rel="noreferrer noopener nofollow" data-darkmysite_alpha_bg="rgba(0, 0, 0, 0)"><strong class="darkmysite_style_txt_border darkmysite_processed" data-darkmysite_alpha_bg="rgba(0, 0, 0, 0)">Telegram, </strong></a><a class="darkmysite_style_txt_border darkmysite_style_link darkmysite_processed" href="https://www.youtube.com/@CoinEngineer" target="_blank" rel="noreferrer noopener nofollow" data-darkmysite_alpha_bg="rgba(0, 0, 0, 0)"><strong class="darkmysite_style_txt_border darkmysite_processed" data-darkmysite_alpha_bg="rgba(0, 0, 0, 0)">YouTube</strong></a>, and <a class="darkmysite_style_txt_border darkmysite_style_link darkmysite_processed" href="https://twitter.com/coinengineers" target="_blank" rel="nofollow noopener" data-darkmysite_alpha_bg="rgba(0, 0, 0, 0)"><strong class="darkmysite_style_txt_border darkmysite_processed" data-darkmysite_alpha_bg="rgba(0, 0, 0, 0)">Twitter</strong></a> channels for the latest <a class="darkmysite_style_txt_border darkmysite_style_link darkmysite_processed" title="News" href="https://coinengineer.net/blog/news/" data-internallinksmanager029f6b8e52c="7" data-darkmysite_alpha_bg="rgba(0, 0, 0, 0)">news</a> and updates.</em></span></p>
<p>The post <a href="https://coinengineer.net/blog/coinmarketcap-removed-malicious-code-threatening-crypto-wallets/">CoinMarketCap Removed Malicious Code Threatening Crypto Wallets </a> appeared first on <a href="https://coinengineer.net/blog">Coin Engineer</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coinengineer.net/blog/coinmarketcap-removed-malicious-code-threatening-crypto-wallets/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url='https://coinengineer.net/blog/wp-content/uploads/2025/05/taslak-ce-2025-05-17T000247.642.png' type='image/webp' medium='image' width='1920' height='1080'><media:title type='plain'> <![CDATA[USA]]></media:title><media:thumbnail url='https://coinengineer.net/blog/wp-content/uploads/2025/05/taslak-ce-2025-05-17T000247.642.png' width='58' height='33' /></media:content>	</item>
	</channel>
</rss>
