Credential Stuffing
Attackers are replaying massive stolen credential sets across business and consumer services to hijack accounts at scale.
Stat: 24B credentials available on dark web
Read Full BriefMalicious scripts are intercepting wallet approvals and draining assets from compromised sites and fake interfaces.
Threat alert
Get the CSM Weekly Threat Brief and updates when this threat profile changes.
Injected scripts prompt wallet users to approve transactions that appear routine but grant sweeping permissions.
Attackers buy traffic, mimic legitimate apps, and use compromised extensions to capture signatures.
The attack path is fast, automated, and often complete before victims realize what was signed.
Retail crypto holders
Creators and communities using wallet-gated tools
Teams experimenting with Web3 integrations
Compromised NFT mint pages with malicious approval flows.
Search ads driving traffic to cloned wallet-connect pages.
Browser extensions altered to inject malicious contract prompts.
Asset loss is often irreversible.
Compromised wallets create long-term trust and identity risk.
Businesses can suffer brand damage if customer wallets are hit through their site.
Use hardware-backed approvals for valuable wallets.
Limit token approvals and review permissions frequently.
Monitor web properties for injected scripts and third-party changes.
Separate experimental wallets from treasury or core accounts.
Vendors
Signal Fraud Ops
Financial Fraud Prevention
Wire fraud controls, anomaly detection, and finance-team verification workflows.
Find More Vendors for This ThreatRelated
Attackers are replaying massive stolen credential sets across business and consumer services to hijack accounts at scale.
Stat: 24B credentials available on dark web
Read Full BriefLLMs are enabling more targeted, more fluent, and more personalized phishing at industrial scale.
Stat: LLMs used to generate hyper-personalized attacks
Read Full BriefAdversaries are manipulating data inputs and training sets to skew AI outputs, trust signals, and downstream decisions.
Stat: Corrupting AI training data to manipulate outputs
Read Full Brief