Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Ethereum Blockchain Exploited to Steal Card Data

Ethereum Blockchain Exploited to Steal Card Data

Posted on August 31, 2026 By CWS

In a sophisticated cyberattack, hackers have utilized the Ethereum blockchain to illicitly obtain credit card information from online shoppers. The method, part of a Magecart campaign identified as HexMage, involves injecting malicious code into the checkout process of compromised e-commerce platforms, leveraging blockchain technology for persistence.

Global Impact of HexMage Campaign

Since April 2026, HexMage has targeted over 40 online merchants across at least 15 countries. The campaign predominantly affects sites using WooCommerce, PrestaShop, Magento, and WordPress, posing significant risks to both merchants and consumers. Analysts from Confiant uncovered the scheme through an analysis of ads originating from affected stores.

Confiant’s report, shared with Cyber Security News, reveals a connection between 20 Sepolia contracts and a singular Ethereum wallet, responsible for deploying numerous contracts between March and July. This highlights a strategic focus on exploiting trusted checkout environments rather than relying on traditional software-based lures.

Technical Details of the Attack

The attackers skillfully disguise a JavaScript loader within a counterfeit Google Tag Manager block, enabling it to blend in with legitimate analytics scripts. Upon checkout initiation, this loader retrieves additional scripts from a content delivery network and communicates with a smart contract on Ethereum’s Sepolia testnet. The contract then supplies a domain for the final skimmer delivery.

This approach, termed EtherHiding, signifies a novel use of public blockchain as a directory for attack infrastructure, complicating detection and prevention efforts. The attackers can seamlessly update the domain used without altering the compromised site’s code, thereby evading simple blocking mechanisms.

Mitigation and Consumer Safety

To mitigate such threats, e-commerce operators are urged to scrutinize server-side modifications, check plugins and admin accounts, and inspect all scripts loaded during the checkout process. Comparing checkout behaviors while logged out and monitoring requests to unfamiliar domains are also recommended practices.

Consumers, on the other hand, should remain vigilant. Successful transactions do not guarantee checkout safety. Those who suspect their card information may have been compromised should immediately contact their card issuer, watch for unauthorized charges, and replace their card if necessary.

The HexMage campaign underscores the vulnerability of online stores and the sophisticated measures attackers employ by using resilient blockchain technology as a cover. Continuous monitoring and proactive security measures are essential for protecting e-commerce platforms and their users.

Cyber Security News Tags:Blockchain, Confiant, credit card theft, Cybersecurity, e-commerce, Ethereum, HexMage, Magecart, Sepolia, smart contracts

Post navigation

Previous Post: Hackers Target Critical Ruby on Rails Flaw for Remote Code Execution
Next Post: ValleyRAT Malware Concealed in Trusted Adware

Related Posts

Gemini API Keys Exploited in Telegram Fraud Scheme Gemini API Keys Exploited in Telegram Fraud Scheme Cyber Security News
TamperedChef Hacking Campaign Leverages Common Apps to Deliver Payloads and Gain Remote Access TamperedChef Hacking Campaign Leverages Common Apps to Deliver Payloads and Gain Remote Access Cyber Security News
Python-based Malware SolyxImmortal Leverages Discord to Silently Harvest Sensitive Data Python-based Malware SolyxImmortal Leverages Discord to Silently Harvest Sensitive Data Cyber Security News
Gujarat Teen Behind 50+ Cyberattacks During ‘Operation Sindoor’ Arrested Gujarat Teen Behind 50+ Cyberattacks During ‘Operation Sindoor’ Arrested Cyber Security News
LexisNexis Risk Solutions Data Breach Exposes 364,000 individuals personal Data LexisNexis Risk Solutions Data Breach Exposes 364,000 individuals personal Data Cyber Security News
Critical ExifTool Vulnerability Exposes macOS to Hidden Threats Critical ExifTool Vulnerability Exposes macOS to Hidden Threats Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Security Threats Highlighted by Hugging Face Breach
  • ValleyRAT Malware Concealed in Trusted Adware
  • Ethereum Blockchain Exploited to Steal Card Data
  • Hackers Target Critical Ruby on Rails Flaw for Remote Code Execution
  • Microsoft Flaw Risks Remote Android Control

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Security Threats Highlighted by Hugging Face Breach
  • ValleyRAT Malware Concealed in Trusted Adware
  • Ethereum Blockchain Exploited to Steal Card Data
  • Hackers Target Critical Ruby on Rails Flaw for Remote Code Execution
  • Microsoft Flaw Risks Remote Android Control

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark