IntegraChain

Market Prices

BTC Bitcoin
$81,057.8 +5.12%
ETH Ethereum
$2,492.11 +4.57%
SOL Solana
$104.02 +4.46%
BNB BNB Chain
$721.6 +5.11%
XRP XRP Ledger
$1.45 +7.53%
DOGE Dogecoin
$0.0874 +7.57%
ADA Cardano
$0.2192 +10.54%
AVAX Avalanche
$7.5 +4.81%
DOT Polkadot
$0.8857 +3.02%
LINK Chainlink
$11.82 +6.80%

Event Calendar

{{年份}}
22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

28
03
unlock Arbitrum Token Unlock

92 million ARB released

18
03
unlock Sui Token Unlock

Team and early investor shares released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

12
05
halving BCH Halving

Block reward halving event

Tools

All →

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$81,057.8
1
Ethereum ETH
$2,492.11
1
Solana SOL
$104.02
1
BNB Chain BNB
$721.6
1
XRP Ledger XRP
$1.45
1
Dogecoin DOGE
$0.0874
1
Cardano ADA
$0.2192
1
Avalanche AVAX
$7.5
1
Polkadot DOT
$0.8857
1
Chainlink LINK
$11.82

🐋 Whale Tracker

🔴
0x5601...22fe
12h ago
Out
895,556 USDT
🟢
0x8d8d...f1ea
2m ago
In
17,109 BNB
🔴
0x5056...9d8a
2m ago
Out
4,044,097 USDC
Products

The CAPTCHA That Drained Wallets: A Forensic Dissection of the StopAndProtect Ransomware Campaign

MoonMax

Over 31,000 screenshots of victims' desktops—including cryptocurrency wallet recovery phrases—were collected by a single threat actor between May and July 2024. The attack vector? A fake CAPTCHA. The infrastructure? Nearly 2,000 compromised WordPress sites. The result? A cold, automated pipeline of credential theft, ransomware deployment, and asset liquidation.

This is not a smart contract exploit. It is a systemic failure of user environment security, and it exposes a truth the crypto industry has been reluctant to face: the chain is secure, but the user is not.

The CAPTCHA That Drained Wallets: A Forensic Dissection of the StopAndProtect Ransomware Campaign

Context: The Attack Chain

Check Point Research published a detailed report on August 21, 2024, dissecting a campaign they dubbed "StopAndProtect." The attack began with a simple social engineering trick: a fake CAPTCHA page hosted on a compromised WordPress site. When a user visited the site, a pop-up appeared, instructing them to copy a PowerShell command and paste it into their terminal. The command downloaded a malicious script that installed a full suite of stealers, keyloggers, and ransomware.

The attackers used the WordPress sites as command-and-control (C2) hubs—hosting malware, storing stolen data, and issuing commands. Over 6,000 unique IPs were infected. The harvested data included credentials, browser cookies, and most critically, cryptocurrency wallet recovery phrases.

The CAPTCHA That Drained Wallets: A Forensic Dissection of the StopAndProtect Ransomware Campaign

Core: The Technical Teardown

Let me walk you through the mechanics. This is not a zero-day vulnerability. It is a brute-force attack on human trust.

Step 1: Compromise the Edge WordPress sites are the weakest link. The attackers likely exploited known vulnerabilities in outdated plugins or themes. No novel code required. Just a scanner and a list of vulnerable sites. Within weeks, they had a distributed network of 2,000 C2 nodes.

Step 2: The Fake CAPTCHA The victim lands on a site. A modal appears: "Please verify you are human. Press Win+R, type 'powershell', then paste the following:" The command is obfuscated—base64, nested loops, variable renaming. To a non-technical user, it looks like a legitimate verification step. It is not. It is a direct instruction to execute malicious code.

Step 3: The Payload Once executed, the PowerShell script downloads a multi-stage payload. It installs: - A credential stealer that scrapes browser password managers. - A keylogger that captures every keystroke, including recovery phrases typed into wallets. - A screenshot tool that captures the entire desktop every 30 seconds. - A network spreader that scans the local network and USB drives, copying the malware to other devices. - Ransomware that encrypts local files and demands payment in Bitcoin.

Step 4: Exfiltration and Monetization All stolen data is sent to the C2 server. The researchers recovered over 31,000 screenshots and 700 compressed archives of stolen files. The recovery phrases are likely checked against on-chain balances automatically. Wallets with non-zero balances are drained within minutes. The chain remembers what the ledger forgets—but the attacker remembers the phrase.

Why This Works From my experience auditing smart contracts, I've learned that the most secure protocol can be undone by the environment it runs on. A user who stores their recovery phrase in a text file on a Windows desktop is vulnerable to any malware that executes on that machine. This attack is not sophisticated. It is efficient. It exploits the gap between the security of the blockchain and the negligence of the user.

The CAPTCHA That Drained Wallets: A Forensic Dissection of the StopAndProtect Ransomware Campaign

Contrarian: What the Bulls Got Right

Some argue that this attack is a testament to the resilience of the blockchain itself—the protocol was not broken, only the user's device. They are technically correct. The Ethereum network processed transactions as designed. The smart contracts remained immutable. The consensus mechanism did not fail.

But this is a hollow victory. The bulls ignore that the promise of self-custody includes the responsibility of securing the private key. If the ecosystem promotes "not your keys, not your coins" without providing the tools to protect those keys, it is a failure of design. This attack proved that even the most paranoid crypto user can be tricked by a fake CAPTCHA. Trust is a variable, not a constant. And the attackers are betting on human error.

Takeaway: Accountability Call

This is not a problem for the blockchain to solve. It is a problem for the entire stack—from WordPress maintainers to wallet vendors to educators. Audits verify intent, not outcome. The code did not lie; it hid behind a CAPTCHA. The real question is: who will take responsibility for the user's environment?

Until hardware wallets become the default, and until operating systems block arbitrary PowerShell execution by default, the attackers will keep draining wallets. The chain remembers what the ledger forgets. And the ledger is full of stolen funds.

Based on my audit experience, I have seen dozens of projects that claim to be "secure by design" but ignore the human factor. StopAndProtect is not a new attack. It is the same old exploit, wrapped in a new interface. The geometry of greed is predictable. The only variable is the user's vigilance.

Fear & Greed

65

Greed

Market Sentiment

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0x7f50...851c
Experienced On-chain Trader
+$1.4M
85%
0xc05a...83fc
Early Investor
+$2.1M
89%
0xcd51...f6dd
Market Maker
+$2.6M
90%