Chaincatcher Gitcoin Subdomain Targeted by Frontend Attack with Phishing Script
Article Content
- •A front-end attack on Gitcoin's subdomain has been detected, involving a phishing script.
- •The malicious code, dubbed 'Eleven drainer,' is aimed at stealing wallet assets.
- •Blockaid has warned users against interacting with the compromised website.
On June 21, 2026, Blockaid reported a front-end attack on the Gitcoin subdomain files.gitcoin.co. The attack involves a malicious code known as 'Eleven drainer,' which is designed to steal wallet assets from users. Blockaid has issued a warning advising users not to interact with the compromised website while investigations and repairs are underway. The exact scope of the impact is currently unknown, but the attack raises significant concerns about user security on the platform. No specific numbers or CVEs have been disclosed at this time. The situation is ongoing, and users are advised to remain vigilant.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Eleven Drainer and Gitcoin in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…