Ethereum Foundation Email Hack Targets Staking Enthusiasts

On Jul 3, 2024 at 2:58 pm UTC by · 2 mins read

The Ethereum Foundation has disclosed that it has been able to regain control of the compromised email address.

The Ethereum Foundation (EF) has issued a security alert to its email subscribers of a recent phishing attack carried out by bad actors. This follows after hackers recently gained access to the organization’s official email account, using the same to send out scam messages that promoted a fake Lido staking program.

The Scam Email

The “updates@blog.ethereum.org” email address was compromised on June 23rd and was subsequently used to send scam emails to at least 35,794 recipients on the day. According to EF, the email deceptively announced that the organization had entered into a partnership with the Lido decentralized autonomous organization (LidoDAO). The partnership, as the scam email cited, was geared towards a supposed staking scheme that will see users earn a massive 6.8% yield on staked crypto (stETH, WETH, or ETH deposits).

The scam email also claimed that the “collaboration” would provide “deep liquidity and competitive rewards” alongside security. It noted that the staking service was “protected and verified” by the Ethereum Foundation.

A “Begin Staking” button was also attached to the email, designed to lead users to the realm of the unknown.

Ethereum Foundation Says Email Hack Damage Was ‘Minimal’

To perfect their scam plot, the attackers created a professional-looking website dubbed “Staking Launchpad”. This website awaited unsuspecting users who clicked the staking button. Anyone who managed to click the button contained in the email would have been redirected to the fake website, which had also been booby-trapped with a drainer that ran in the background. Upon clicking, users were prompted to approve a transaction in their crypto wallet. Whereas, granting such approval would have resulted in the complete removal of funds within their accounts.

On the bright side, though, the Ethereum Foundation has disclosed that it has been able to regain control of the compromised email address. That is before it caused widespread financial losses. Fortunately, investigations revealed that this particular attempt by attackers did not yield any tangible results for them. According to EF, the email hack did not result in any financial loss. However, it did expose the email addresses of 81 subscribers who were not part of the original mailing list.

Not leaving anything to chance, the Ethereum Foundation has taken proactive measures by contacting major wallet providers, blacklisting services, and DNS provider Cloudflare. This collaboration aims to warn users and prevent further exploitation through the fake website.

Share:

Related Articles

3 Reasons Bitcoin Price Failed to Cross $120K Despite Ethereum All-Time High Rally

By August 23rd, 2025

Bitcoin price missed the $120,000 breakout target while Ethereum approached all-time highs near $4,900, with market data revealing three key reasons for BTC’s underwhelming performance.

Whales Ditching Bitcoin for Ether, Altcoin Rally Ahead?

By August 22nd, 2025

While Bitcoin is holding on to the $113,000 level, large investors are continuously shifting to Ethereum.

ETH Rises as Singapore’s DBS Unveils Tokenized Notes on Ethereum

By August 21st, 2025

Ethereum climbed back to the $4,300 zone as the largest Singaporean bank hints at tokenized notes on the network.

Exit mobile version