Free tools Windows power users keep installed
One-click scans. No signup required.
On April 24, 2018, attackers redirected some people trying to visit myetherwallet.com to a convincing imitation of MyEtherWallet (MEW). The incident was not a breach of a centralized MEW vault: MEW is a self-custody service, so the attackers stole funds after victims entered private keys, recovery phrases or keystore credentials into the fake site.
Early reports estimated about $150,000, or 216 ETH, was stolen. Later blockchain tracking found about 520 ETH entering two wallets associated with the campaign, although that larger total was not necessarily all from this incident. The exact final loss was never conclusively established.
What happened on April 24, 2018?
MEW said the incident began at approximately 12:00 UTC. Visitors who typed the genuine domain could receive a malicious IP address instead of MEW’s real server. The resulting page copied MEW’s appearance and prompted users to unlock wallets. Some browsers displayed a certificate warning; users who bypassed it and entered wallet credentials exposed their assets.
MEW described the event as a DNS-server hijacking. RiskIQ’s technical analysis was more specific: attackers used a Border Gateway Protocol (BGP) hijack affecting Amazon Route 53 infrastructure to reroute DNS traffic and deliver the phishing host.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- All your digital assets in one place. You can manage thousands of crypto including Bitcoin, Ethereum, Solana, Tether and more.
- Defend your identity against hackers: secure your online accounts with passwordless, hardware backed, 2FA logins for all your favorite apps and websites.
- Connectivity: USB-C cable connection only. No Bluetooth.Compatible with the Ledger Wallet crypto app, both desktop (Windows, macOS, Linux) and mobile (Android only). Not compatible with iOS.
- Protect your digital assets with the industry's best security: keep your private keys offline in your private signer, battle-tested by the Donjon's white hat hackers, CC EAL 6+ certified Secure Element, constantly updated Ledger OS.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
DNS hijacking versus BGP hijacking
DNS translates a name such as myetherwallet.com into an IP address. BGP determines how networks announce and route IP traffic across the internet. In this case, manipulation of routing affected DNS responses, so the user-facing symptom was a wrong website even though the underlying redirection involved BGP.
The incident therefore was not evidence that Google Public DNS itself had been breached. Contemporary reports said many affected users were using Google’s resolver, while MEW later advised temporarily switching to Cloudflare during its response.
How the phishing site drained wallets
RiskIQ called the attack kit MEWKit. It combined a visual copy of MEW with credential collection, server-side logging and wallet-destination management, plus client-side automation that could initiate Ethereum transfers after a victim authenticated.
Rank #2
- All your digital assets in one place. You can manage thousands of crypto including Bitcoin, Ethereum, Solana, Tether and more.
- Connectivity: USB-C cable connection only. No Bluetooth.Compatible with the Ledger Wallet crypto app, both desktop (Windows, macOS, Linux) and mobile (Android only). Not compatible with iOS.
- Protect your digital assets with the industry's best security: keep your private keys offline in your private signer, battle-tested by the Donjon's white hat hackers, CC EAL 6+ certified Secure Element, constantly updated Ledger OS.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Choose the colors that match your style: express your personality and your crypto management mood, color code your signers, one for each use (trading, staking, HOLDing...).
- The user entered the MEW domain.
- Manipulated routing caused a malicious DNS response.
- The browser loaded a counterfeit MEW interface.
- The victim supplied a private key, mnemonic phrase or JSON/keystore file and password.
- MEWKit sent ether or Ethereum-based tokens to attacker-controlled addresses.
This was more than a page collecting information for later resale: the kit was designed to move funds quickly after credentials were entered.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Was MEW itself hacked?
Not in the sense of a centralized customer database being breached. MEW says it does not hold users’ keys or funds. The attacker reached users before they reached the genuine client-side application, then persuaded some of them to disclose the material that controls their wallets. The blockchain and MEW’s underlying wallet code were not required to be compromised.
That distinction matters for self-custody. The provider cannot retrieve a private key entered into a fraudulent page, and it generally cannot reverse a confirmed blockchain transfer.
Rank #3
- All your digital assets in one place. You can manage thousands of crypto including Bitcoin, Ethereum, Solana, Tether and more.
- Connectivity: USB-C cable connection only. No Bluetooth.Compatible with the Ledger Wallet crypto app, both desktop (Windows, macOS, Linux) and mobile (Android only). Not compatible with iOS.
- Protect your digital assets with the industry's best security: keep your private keys offline in your private signer, battle-tested by the Donjon's white hat hackers, CC EAL 6+ certified Secure Element, constantly updated Ledger OS.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Choose the colors that match your style: express your personality and your crypto management mood, color code your signers, one for each use (trading, staking, HOLDing...).
How much cryptocurrency was lost?
| Estimate | What it represents | Qualification |
|---|---|---|
| About $150,000 (216 ETH) | CoinDesk’s early report | Initial estimate on April 24, 2018 |
| About 520 ETH (roughly $365,000 at the time) | Two wallets identified by later transaction tracking | Not necessarily all attributable to this single campaign |
Multiple addresses and uncertain attribution made a definitive total difficult to establish. It is more accurate to describe the first figure as an initial estimate and the second as tracked inflows than to present either as a final audited loss.
Who was most exposed?
| Wallet method | What the phishing page could obtain | Practical exposure |
|---|---|---|
| Raw private key | The key itself | Assume the entire wallet is compromised |
| Mnemonic or recovery phrase | The wallet’s master secret | All accounts derived from it are at risk |
| JSON/keystore upload plus password | Encrypted key material and its password | Attackers could unlock and transfer funds |
| Hardware wallet connection | Normally not the private key | Extraction risk is reduced, but a user can still approve a bad transaction |
A hardware wallet keeps signing keys on the device, so a fake webpage cannot simply read them. It does not, however, make a malicious destination safe. Users must inspect the address and transaction details shown on the hardware device and reject anything unexpected.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteWhat the certificate warning meant
MEW urged users to verify a valid certificate associated with “MyEtherWallet Inc.” A browser warning indicated that the connection was not safely authenticated and should never have been bypassed while entering wallet credentials.
Rank #4
- Bitcoin Hardware Wallet Case for Ledger Nano X/ S/ S Plus Cryptocurrency Hardware Wallet - BTC Bitcoin, Ethereum, Ripple, Altcoins and ERC Tokens
- Featured Design: Strong compact light weight all in one case to keep the Bitcoin Hardware Wallet and other small accessories well organized and protected; fit purse, shoulder bag, suite case. good for home storage and travel carrying
- Assured Protection: Semi-hard carrying case protecting the device from shock, shake, scratch. PEVA materials with pressure or hit absorbing and water resistant
- Only protective case for sales, Device or accessories sold separately.
A padlock is not proof of authenticity. A phishing domain can obtain a valid certificate for its own name. Navigate to a known-good official domain or bookmark rather than using a search advertisement, social-media link or unsolicited message.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What MEW changed afterward
In its June 2018 account, MEW said it secured the affected service, investigated the targeted servers, migrated DNS arrangements to Cloudflare and added or emphasized registrar lock, registry lock, HSTS, DNSSEC, CDN and DDoS protections. Those measures reduce risk at the domain and DNS layers; they do not make phishing, malware, malicious browser extensions or social engineering impossible.
MEW’s current materials describe access through MEW Mobile, Enkrypt and supported hardware wallets, and its recent help guidance says online entry of a keystore, mnemonic or private key is not recommended. Current products should not be projected backward as though they were the architecture involved in 2018.
Best Value
- All your digital assets in one place. You can manage thousands of crypto including Bitcoin, Ethereum, Solana, Tether and more.
- Defend your identity against hackers: secure your online accounts with passwordless, hardware backed, 2FA logins for all your favorite apps and websites.
- Protect your digital assets with the industry's best security: keep your private keys offline in your private signer, battle-tested by the Donjon's white hat hackers, CC EAL 6+ certified Secure Element, constantly updated Ledger OS.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Choose the colors that match your style: express your personality and your crypto management mood, color code your signers, one for each use (trading, staking, HOLDing...).
What victims should do
- Stop using the affected wallet. Do not send more funds to it.
- Create a new wallet on a clean device with a new recovery phrase.
- Move any remaining assets to the new wallet, checking every destination carefully.
- Never reuse the exposed key, phrase or keystore. Changing a DNS provider does not repair a compromised key.
- Preserve evidence: transaction hashes, addresses, timestamps, screenshots and the suspected URL.
- Contact MEW through its official support channel and provide the evidence requested.
- Notify an exchange or custodian if stolen funds reach its deposit address; an exchange may be able to flag or freeze funds under its own procedures.
- Report the incident to appropriate law-enforcement or cybercrime authorities.
- Ignore recovery agents. Anyone demanding an upfront fee or a new private key to “recover” funds is a likely second-stage scam.
MEW says it cannot freeze, reverse or refund confirmed blockchain transactions. Support can still help document an incident and identify scam patterns.
How to protect a self-custody wallet today
- Use a hardware wallet for substantial long-term holdings, buy it directly from the manufacturer, and verify each transaction on the device.
- Keep recovery phrases offline; never type them into a website, chat, form or support ticket.
- Use software-wallet imports, if unavoidable, offline and only with software obtained from a verifiable source.
- Type or bookmark the official domain and independently check the spelling before connecting a wallet.
- Never bypass a certificate warning.
- Separate a wallet used for experimental dApps from a wallet holding long-term savings.
- Remember that DNSSEC, registrar locks and HTTPS protect infrastructure or transport, not your judgment at the signing screen.
These controls involve trade-offs. Self-custody removes an intermediary’s control but makes key management your responsibility. Exchange custody may offer account support or fraud monitoring while adding account-takeover, withdrawal-freeze, counterparty and solvency risks.
The lasting lesson
The 2018 MEW incident showed how an intact blockchain can coexist with a compromised path to the wallet interface. Attackers did not need to break Ethereum or empty a MEW database; redirecting traffic and capturing signing credentials was enough. For every self-custody wallet, the decisive safeguards are an independently verified connection, offline key protection and deliberate confirmation of every transaction.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




