MyEtherWallet (), the most popular web-based wallet fell victim to a DNS hack on April 24, 2018. Comments made by wallet users on social media and online crypto forums reveal that funds have indeed been stolen from their wallets. , a rival service to MEW, confirmed the occurrence of the hack and informed MEW users that their accounts had been compromised. This is yet another DNS-based attack in the crypto community which shows the vulnerability inherent in a single point of failure. , for instance, was the of a similar hack in December 2017.
Reports of Missing Funds from Wallet Users
It began when MEW users started reporting suspicious activities on the MEW web interface. The news was broken by a MEW-user on Reddit , saying that they had to a phishing scam. Apparently, the user had logged on the MEW service and seen that the connection was not secure which was an anomaly.
(Source: )
The user proceeded to check if the site was a phishing site but all checks proved negative and despite their better judgment, proceeded to log in. The user ended up losing 0.09 ETH which was all the money that was in the user’s wallet.
Not too long after the story broke, MEW published a confirmation tweet. Earlier in the year, MEW had rumors that it had been hacked. This time around, it appears the wallet provider had indeed been breached.
Couple of DNS servers were hijacked to resolve users to be redirected to a phishing site. This is not on side, we are in the process of verifying which servers to get it resolved asap.
— MyEtherWallet.com (@myetherwallet)
An address linked to the hack has been discovered, and it is currently on Etherscan (Fake_Phishing899) as being involved in the MEW DNS hack. The address has so far conducted 180 transactions and has stolen 215 ETH currently valued at . According to a on Reddit, there are indications that the hack may have originated from Russia.
(Source: )
DNS Down and Confirmation from Rival Service
MEW isn’t the only crypto service experiencing DNS troubles. In the early hours of April 21, Binance tweeted that Google’s DNS service was down and that this was the reason for the service disruptions experienced by some of the exchange’s users. There are no indications yet whether the two incidents are related. However, a tweet by CobraBitcoin (co-owner of ) revealed that the Google DNS issues could have a link to the MEW hack.
Sounds like something very evil has happened with Google DNS today. Their DNS servers appear to have been compromised and used to phish users at services like . Don't trust any website if you're using Google DNS. Even SSL certificates can be generated at DNS level.
— Cøbra (@CobraBitcoin)
MyCrypto also posted confirming the MEW DNS hack. Being direct competitors of MEW, MyCrypto spared few details in what may seem like a bit of “schadenfreude” over the current travails of its rival. It should also be noted that MyCrypto as a result of a less than harmonious split between the founders of the MEW earlier in the year.
A summary of what to do in case you’ve used in the last ~4 hours:
— MyCrypto.com (@MyCrypto)
According to MyCrypto, the account of any MEW user who entered their private key during the hack has been compromised. As a result, the service is doing all it can to mobilize resources to investigate the cause of the attack and try to help the MEW team in any way that it can. The MyCrypto team also advised wallet users to store their funds in offline wallets to keep them safe from hackers.
We advise all our readers to prefer using whenever possible and to make sure that SSL certificate is green when using any important website. Investing in a hardware wallet like or is beneficial since all online exchanges and wallets can be hacked.
The post appeared first on .

Der amerikanische Bankenriese Goldman Sachs erweitert seinen Marktbereich offiziell mit Krypto-Expertise. Berichten zufolge wird der Trader Justin Schmidt neuer Abteilungsleiter im digitalen Anlagengeschäft der Bank. Vorzeichen einer kommenden Krypto-Abteilung, wie sie im vergangenen Jahr vorausgesehen worden ist, sollen dies jedoch nicht sein. Mit der Einstellung wolle man lediglich dem gestiegenen Kundeninteresse im Bereich Kryptowährungen begegnen,…Der Beitrag erschien zuerst auf .

