DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
Blog

Ethereum Foundation Mailing List Compromised to Send 35,794 Phishing Emails

By TheFinanceBase Team5 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

On June 23, 2024, an attacker used access to the Ethereum Foundation’s mailing-list service to send a wallet-draining phishing email to 35,794 email addresses. It came from the legitimate address [email protected] and promoted a Lido-related scam. The Foundation said its on-chain review appeared to show no funds lost during the campaign window, but the incident was a real abuse of trusted communications infrastructure—not a reported hack of Ethereum’s blockchain.

What happened in the Ethereum Foundation email incident?

At 00:19 UTC on June 23, 2024, a phishing message was sent to 35,794 email addresses through the Foundation’s blog mailing list. The Foundation’s July 2 incident notice says the attacker gained access into the mailing-list provider and used the service to send the message. SecurityWeek reported the incident on July 8, describing it as a compromise of an Ethereum Foundation account on a mailing-list platform. The exact count is 35,794 addresses; “35,000” is a rounded headline figure, not a confirmed count of individual people.

The email came from [email protected], a Foundation-controlled sender address, and promoted a fraudulent Lido-related offer. Its link led to a malicious site containing a crypto drainer. The sender’s legitimacy made the message more convincing, but did not make its offer or destination safe. The Ethereum Foundation’s incident notice provides the campaign details; SecurityWeek’s July 8 report also characterizes the lure as a Lido scam.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Was Ethereum or Lido hacked?

The reported compromise involved access to the Ethereum Foundation’s mailing-list service. It was not described as a breach of Ethereum’s blockchain, consensus mechanism, or protocol, and the available notice does not report that Foundation cryptocurrency wallets were compromised. The provider, initial access method, and attacker’s identity were not publicly identified in the notice.

#1 Best Overall
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

The email used Lido branding or a Lido-related offer, but that is not evidence that Lido participated in the campaign or that its systems were breached. The incident notice likewise does not establish that Lido was involved.

How could the phishing site drain a wallet?

A crypto drainer is designed to trick a user into authorizing wallet actions that transfer assets or grant a site permission to move tokens. In this campaign, the stated danger was a malicious website prompting a wallet connection and a transaction signature. The risk was not simply that an email arrived or that a link was clicked: the wallet interaction and authorization were the crucial steps described by the Foundation.

Rank #2
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.
  • Connecting a wallet lets a site request wallet actions and may reveal the wallet’s public address; by itself, this is different from authorizing a transfer.
  • Signing a message confirms a cryptographic message. Its implications depend on what is being signed, so unfamiliar prompts should not be treated as harmless.
  • Approving a token allowance can authorize a spender to move tokens within the approved terms.
  • Signing a transaction authorizes an on-chain action, which may transfer assets or change permissions.

Never approve a wallet prompt you do not understand. A genuine sender address does not validate the link, website, or requested signature.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What mailing-list information was exposed?

The Foundation said the attacker imported a large email list already in the attacker’s possession and exported the Foundation blog mailing list, which contained 3,759 addresses. Comparing the lists, investigators found that 81 addresses in the Foundation list were not previously known to the attacker; the rest duplicated addresses in the imported list.

Rank #3
SecuX PUFido USB-C Security Key with PUF Technology, FIDO2/U2F Certified, Hardware-Rooted Unclonable Security for Passwordless Login and 2FA Authentication
  • A FIDO security key with PUF technology provides a unique, hardware-rooted trust anchor that resists tampering and cyber attacks, offering stronger security than conventional designs.
  • FIDO2 Certified Protection – Enjoy phishing-resistant security with FIDO2 certification, ensuring top-tier account safety across Windows, macOS, Linux, iOS iOS, Android and more.
  • Easy to use & Portable – Designed with a compact USB-C interface, Clife key fits easily on your keychain for secure access anywhere. Simply plug in and authenticate with ease.
  • Universal Compatibility – Works seamlessly with hundreds of FIDO2/U2F compliant services, including popular cloud, email, and social platforms.
  • Backup recommended – To ensure continuous access, register a backup Clife security key as a spare in case your primary key is lost.

The notice confirms exposure of email addresses. It does not report that passwords, seed phrases, private keys, payment details, or account credentials were taken. The 81 figure describes addresses newly exposed to this attacker according to the Foundation’s comparison; it is not a count of people whose credentials were stolen.

Did anyone lose cryptocurrency?

The Foundation said its review of on-chain transactions between the email campaign and the blocking of the malicious domain appeared to show that no victims lost funds during that specific campaign window. This is the Foundation’s time-bounded assessment, not proof that nobody clicked, that the drainer could not work, or that no one experienced harm outside the analyzed period. The notice does not provide counts of email opens, wallet connections, or signatures, nor an independent verification of the no-loss finding.

Rank #4
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

How did the Foundation respond?

The Foundation said it stopped further mailings, warned users through Twitter and email, closed the malicious access path into the mailing-list provider, and submitted the malicious URL to blocklists. It also reported that most Web3 wallet providers and Cloudflare blocked the domain, migrated some mail services to other providers, and continued investigating with internal and external security teams. A block reduces the chance of reaching a known malicious domain; it does not make a copied or redirected link safe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should recipients do?

If you received the email but did nothing

  • Do not click the link; delete or report the message.
  • Verify future announcements by opening the official site yourself or checking an independently verified social account, rather than relying on the sender address alone.

If you clicked but did not connect a wallet

  • Close the page and do not download files or accept browser prompts from it.
  • If you granted site permissions, remove suspicious permissions in your browser settings and run your usual device and browser security checks.
  • Be alert for follow-up phishing messages, which may use knowledge that you engaged with the first lure.

If you connected a wallet or signed something

  • Review the prompt and wallet activity. If you authorized an unfamiliar transaction or token allowance, treat the wallet as potentially exposed.
  • From a reputable tool reached independently—not through the email—revoke suspicious token approvals. Revocation cannot reverse a transfer that has already completed.
  • If you signed an unknown or malicious transaction, especially one granting broad permissions, consider moving remaining assets to a new wallet whose recovery phrase has never been entered on the suspect site.
  • Save the email, URL, timestamps, and transaction hashes, and contact your wallet provider, exchange, or a qualified incident-response service.
  • Do not pay anyone promising guaranteed recovery of stolen cryptocurrency.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What this incident means for mailing-list security

The breach shows why trusted sender infrastructure can become a phishing channel: users may lower their guard when a message arrives from an address they recognize. For organizations, mailing-list access deserves controls comparable to other systems that can reach customers or members.

Best Value
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
  • Require multifactor authentication and use least-privilege access for mailing-list administrators.
  • Restrict and monitor list exports, API keys, and sessions; remove credentials and access that are no longer needed.
  • Use approval workflows or anomaly alerts for unusual bulk sends, new campaign content, or unexpected exports.
  • Maintain a separate, independently controlled channel for urgent security notices so a compromised mail platform is not the only way to communicate.

What remains unknown

The public notice does not name the mailing-list vendor or explain whether access came from stolen credentials, an API key, session hijacking, or a provider-side vulnerability. It does not identify the attacker or malicious domain, quantify opens or wallet interactions, establish whether the attacker retained exported addresses, or report whether anyone was targeted later. Those details should not be inferred from the sender address or the Lido theme.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.