CoinGecko report a data breach of 2 million users due to a third-party hack
The accounts on the aggregator’s own platform are safe, the hacker did not gain access to the passwords
07.06.2024 - 15:35
861
2 min
0
What’s new? The team at the leading cryptocurrency market data aggregator CoinGecko has reported a leak of user data caused by a hack of the third-party email platform GetResponse. An attacker hacked into the account of one of the GetResponse employees and thus gained access to the information.
What else is known? The leak was discovered on June 5 and confirmed by GetResponse on June 6. The hacker exported 1 916 596 contacts from a CoinGecko account on the GetResponse platform and sent phishing emails to 23 723 addresses.
The incident compromised personal information including username, email address, IP address, email login location, and other metadata including account registration date and paid subscription plan.
However, CoinGecko assured that accounts on the aggregator’s own platform remain safe as the hacker did not access the passwords. The team directly notified users affected by the leak via email.
CoinGecko apologized for the incident and urged caution when opening emails due to the risk of a phishing attack. Any airdrop eligibility notifications from CoinGecko or GeckoTerminal are a scam, as the platform has not officially issued any tokens.
“We are thoroughly reviewing our security procedures and will look to enhance our security protocols in collaboration with our vendors,” the company concluded.
This is not the first time the platform has encountered fraud. In January, hackers broke into CoinGecko’s X accounts and posted fake claims about the launch of a native token. Phishing links were attached to the posts purportedly to connect a wallet and receive free coins, interaction with which could result in the loss of all assets.
In 2022, a malicious pop-up window appeared on CoinGecko and other cryptocurrency portals offering to connect a crypto wallet, which also led to a phishing site to steal assets.
Useful material?
Incidents
Developers warned of potential risks to bridges across the ecosystem and asked exchanges for assistance.
Jun 22, 2026
Incidents
The defendant helped move funds stolen through investment scams and earned at least $4 million for his role in the operation.
Jun 10, 2026
Incidents
The company is linking the incident to a compromised private key on a service wallet, rather than a smart contract exploit
May 22, 2026
Incidents
Following the incident, the project temporarily halted trading operations and node activity.
May 15, 2026
Incidents
The user spent weeks unsuccessfully trying to guess the password until Claude helped find an old wallet backup file
May 14, 2026
Crypto regulations
Authorities are introducing mandatory registration for companies handling cross-border crypto transactions
May 8, 2026
Telegram
Twitter