<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Ethereum_Foundation_Mailing_List_Phishing</id>
	<title>Ethereum Foundation Mailing List Phishing - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Ethereum_Foundation_Mailing_List_Phishing"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Ethereum_Foundation_Mailing_List_Phishing&amp;action=history"/>
	<updated>2026-05-30T05:54:12Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Ethereum_Foundation_Mailing_List_Phishing&amp;diff=6111&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/ethereumfoundationmailinglistphishing.php}} {{Unattributed Sources}}  Ethereum Foundation Logo/HomepageLate in the afternoon of June 22nd, an email was sent to 35,794 people, including at least 3,759 email addresses from the Ethereum Foundation's mailing list. The email offered respondents 6.8% APY return from staking in the Lido protocol through a p...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Ethereum_Foundation_Mailing_List_Phishing&amp;diff=6111&amp;oldid=prev"/>
		<updated>2024-09-18T21:55:47Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/ethereumfoundationmailinglistphishing.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Ethereumfoundation.jpg&quot; title=&quot;File:Ethereumfoundation.jpg&quot;&gt;thumb|Ethereum Foundation Logo/Homepage&lt;/a&gt;Late in the afternoon of June 22nd, an email was sent to 35,794 people, including at least 3,759 email addresses from the Ethereum Foundation&amp;#039;s mailing list. The email offered respondents 6.8% APY return from staking in the Lido protocol through a p...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/ethereumfoundationmailinglistphishing.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Ethereumfoundation.jpg|thumb|Ethereum Foundation Logo/Homepage]]Late in the afternoon of June 22nd, an email was sent to 35,794 people, including at least 3,759 email addresses from the Ethereum Foundation's mailing list. The email offered respondents 6.8% APY return from staking in the Lido protocol through a partnership with the Ethereum Foundation. There was no push for urgency or limited time offer in the email, and the Ethereum Foundation notified users of the phishing with a follow up email shortly thereafter. Blockchain analysis shows that no users have fallen for the attack, and no funds were lost.&amp;lt;ref name=&amp;quot;rektnews-14663&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;ethereum-14664&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;ethereum-14665&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;ethereum-14666&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;timbeikotwitter-14667&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;sendpulsecomtwitter-14668&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;timbeikotwitter-14669&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;fivedogittwitter-14670&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;bleepingcomputer-14671&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About Ethereum Foundation ==&lt;br /&gt;
&amp;quot;The Ethereum Foundation(opens in a new tab) (EF) is a non-profit organization dedicated to supporting Ethereum and related technologies.&lt;br /&gt;
&lt;br /&gt;
The EF is not a company, or even a traditional non-profit. Their role is not to control or lead Ethereum, nor are they the only organization that funds critical development of Ethereum-related technologies. The EF is one part of a much larger ecosystem.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Our vision for Ethereum is the Infinite Garden. Ethereum is more than a technology, it is a diverse ecosystem of individuals and organizations that build and grow alongside a protocol. The Ethereum ecosystem wasn't something that was designed by any one individual or organization, but it organically evolved with the support of people who nurture the ecosystem to become more vibrant and diverse.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;We are proudly bringing the Ethereum community an innovative and secure way to stake with Lido.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Now, you can earn a remarkable 6.8% APY on your stETH, wETH, or ETH deposits, all while enjoying the peace of minde that comes with best in blass security.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;This collaboration harnesses the strengths of both organizations to deliver deep liquidity and competitive rewards, enhancing your staking experience with over 100+ integrations. Together, we are selling a new standard for decentralized finance, providing a secure, transparent, and resilient protocol that empowers the Ethereum community like never before.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Protected and Verified by the Ethereum Foundation&amp;quot; &amp;quot;Over 100+ integrations&amp;quot; &amp;quot;Best in-clas ssecurity&amp;quot; &amp;quot;Transparent and Resilient Protocol&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;This is just the beginning. We are committed to delivering a seamless and rewarding experience for all Ethereum users, and we are excited to continue building the future of decentralized finance together.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Join us in this exciting new chapter of Ethereum's journey.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
This sections is included if a case involved deception or information that was unknown at the time. Examples include:&lt;br /&gt;
&lt;br /&gt;
* When the service was actually started (if different than the &amp;quot;official story&amp;quot;).&lt;br /&gt;
* Who actually ran a service and their own personal history.&lt;br /&gt;
* How the service was structured behind the scenes. (For example, there was no &amp;quot;trading bot&amp;quot;.)&lt;br /&gt;
* Details of what audits reported and how vulnerabilities were missed during auditing.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
&amp;quot;The attack occurred on the night of June 23 when an email was sent from the address ‘updates@blog.ethereum.org' to 35,794 addresses.&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - Ethereum Foundation Mailing List Phishing&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|June 22nd, 2024 6:19:00 PM MDT&lt;br /&gt;
|Email Phishing Campaign&lt;br /&gt;
|The email phishing campaign sends to thousands of recipients.&lt;br /&gt;
|-&lt;br /&gt;
|June 22nd, 2024 7:47:00 PM MDT&lt;br /&gt;
|Account Hack Tweet&lt;br /&gt;
|Tim Beiko of the Ethereum Foundation notifies that is appears the mailing list provider may have been compromised and includes a screenshot of the email which was received.&lt;br /&gt;
|-&lt;br /&gt;
|June 22nd, 2024 7:55:00 PM MDT&lt;br /&gt;
|Nansen Address Used&lt;br /&gt;
|User reports that their Nansen email address was used for the phishing attack.&lt;br /&gt;
|-&lt;br /&gt;
|June 22nd, 2024 9:41:00 PM MDT&lt;br /&gt;
|Account Locked Down&lt;br /&gt;
|The Ethereum Foundation updates Twitter to indicate that they believe they've locked down the account, they sent an update to all subscribers warning them about the phishing link, and&lt;br /&gt;
|-&lt;br /&gt;
|June 25th, 2024 4:52:00 AM MDT&lt;br /&gt;
|SendPulse Investigation Tweet&lt;br /&gt;
|SendPulse shares an update to indicate that the email was snet through a Google Workspace account, and not any of the SendPulse infrastructure.&lt;br /&gt;
|-&lt;br /&gt;
|July 2nd, 2024&lt;br /&gt;
|Ethereum Foundation Blog Post&lt;br /&gt;
|The Ethereum Foundation shares a blog post with details of the phishing campaign and their investigation.&lt;br /&gt;
|-&lt;br /&gt;
|July 4th, 2024 10:17:29 AM MDT&lt;br /&gt;
|Bleeping Computer Article&lt;br /&gt;
|Bleeping Computer shares an article on the phishing attack.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
&amp;quot;In June, a threat actor compromised Ethereum's mailing list provider and sent to over 35,000 addresses a phishing email with a link to a malicious site running a crypto drainer.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The results of the investigation into the incident involving unauthorized access to the Ethereum Foundation account show that a Google Workspace account was used for the breach. There is no evidence that the SendPulse infrastructure or other users’ accounts were compromised.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Ethereum says that the threat actor used a combination of their own email address list and an additional 3,759 exported from the platform's blog mailing list. However, only 81 of the exported addresses were previously unknown to the attacker.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
&amp;quot;On-chain transaction analysis showed that none of the email recipients fell for the trap during the campaign.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
No funds were lost.&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
&amp;quot;Ethereum disclosed the incident in a blog post and said that it had no material impact on users.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;it seems like the mailing list provider the EF uses for &amp;quot;updates@ethereum.org&amp;quot; has been compromised. We are currently trying to reach @SendPulseCom to resolve the issue. Please don't click any links sent from that email.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Ethereum says that its internal security team launched an investigation as soon as possible to identify the attacker, understand the attack's purpose, determine the timeline, and identify the affected parties.&lt;br /&gt;
&lt;br /&gt;
The attacker was quickly blocked from sending more emails and Ethereum took to Twitter to notify the community about the malicious emails, warning everyone not to click the link.&lt;br /&gt;
&lt;br /&gt;
Ethereum also submitted the malicious link to various blocklists, which led to it being blocked by most Web3 wallet providers and Cloudflare.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
&amp;quot;Ethereum concludes by saying it has taken additional measures and is migrating some email services to other providers to prevent such an incident from happening again.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The results of the investigation into the incident involving unauthorized access to the Ethereum Foundation account show that a Google Workspace account was used for the breach. There is no evidence that the SendPulse infrastructure or other users’ accounts were compromised.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;rektnews-14663&amp;quot;&amp;gt;[https://rekt.news/cryptos-achillesheel/ Rekt - Crypto's Achilles' Heel] (Accessed Jul 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;ethereum-14664&amp;quot;&amp;gt;[https://ethereum.org/en/foundation/ Ethereum Foundation | ethereum.org] (Accessed Jul 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;ethereum-14665&amp;quot;&amp;gt;[https://ethereum.foundation/ https://ethereum.foundation/] (Accessed Jul 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;ethereum-14666&amp;quot;&amp;gt;[https://ethereum.foundation/infinitegarden https://ethereum.foundation/infinitegarden] (Accessed Jul 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;timbeikotwitter-14667&amp;quot;&amp;gt;[https://twitter.com/TimBeiko/status/1804721462407725441 @TimBeiko Twitter] (Accessed Jul 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;sendpulsecomtwitter-14668&amp;quot;&amp;gt;[https://twitter.com/SendPulseCom/status/1805554639036658057 @SendPulseCom Twitter] (Accessed Jul 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;timbeikotwitter-14669&amp;quot;&amp;gt;[https://twitter.com/TimBeiko/status/1804693090944553186 @TimBeiko Twitter] (Accessed Jul 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;fivedogittwitter-14670&amp;quot;&amp;gt;[https://twitter.com/fivedogit/status/1804694756435407236 @fivedogit Twitter] (Accessed Jul 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;bleepingcomputer-14671&amp;quot;&amp;gt;[https://www.bleepingcomputer.com/news/security/ethereum-mailing-list-breach-exposes-35-000-to-crypto-draining-attack/ Ethereum mailing list breach exposes 35,000 to crypto draining attack] (Accessed Jul 12, 2024)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>