Loading market data...

Something like

Something like

An operation called 'StopAndProtect' is using nearly 2,000 hacked WordPress sites to steal crypto wallets, according to details of the campaign. The scale of the effort points to a coordinated attack on web infrastructure, and it's a reminder that crypto security doesn't stop at the exchange or the wallet app.

The scale of the operation

The campaign has compromised close to 2,000 WordPress installations. That's a large network of sites, all being used for one purpose: siphoning crypto from unsuspecting users. Each site is a potential trap, and the sheer number means the attack surface is huge.

WordPress is one of the most popular content management systems on the internet, so the choice of platform makes sense. But the operation also shows how a single unpatched vulnerability can be exploited at scale.

A patch problem

The 'StopAndProtect' operation highlights a well-known but often ignored issue: patch management. Many WordPress sites run outdated plugins or themes, and that's exactly the kind of weakness these attackers look for. Once a site is compromised, it becomes a tool for wallet theft.

For anyone running a WordPress site that touches crypto — a merchant page, a blog, a forum — the takeaway is direct. If you haven't updated your installation in a while, now is the time. The cost of a patch is nothing compared to the cost of a drained wallet.

The broader impact

This isn't just a problem for the site owners whose pages got hacked. It's a problem for anyone who visits those pages and ends up with a stolen wallet. The operation shows how a vulnerability in one part of the web can ripple out and hurt people who had nothing to do with the site's maintenance.

The need for better cybersecurity measures is urgent. That means keeping software current, but it also means being careful about where you connect your wallet and what you click when you're on a less-than-trustworthy page.