Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Ethereum Blockchain Exploited to Steal Card Data

Ethereum Blockchain Exploited to Steal Card Data

Posted on August 31, 2026 By CWS

In a sophisticated cyberattack, hackers have utilized the Ethereum blockchain to illicitly obtain credit card information from online shoppers. The method, part of a Magecart campaign identified as HexMage, involves injecting malicious code into the checkout process of compromised e-commerce platforms, leveraging blockchain technology for persistence.

Global Impact of HexMage Campaign

Since April 2026, HexMage has targeted over 40 online merchants across at least 15 countries. The campaign predominantly affects sites using WooCommerce, PrestaShop, Magento, and WordPress, posing significant risks to both merchants and consumers. Analysts from Confiant uncovered the scheme through an analysis of ads originating from affected stores.

Confiant’s report, shared with Cyber Security News, reveals a connection between 20 Sepolia contracts and a singular Ethereum wallet, responsible for deploying numerous contracts between March and July. This highlights a strategic focus on exploiting trusted checkout environments rather than relying on traditional software-based lures.

Technical Details of the Attack

The attackers skillfully disguise a JavaScript loader within a counterfeit Google Tag Manager block, enabling it to blend in with legitimate analytics scripts. Upon checkout initiation, this loader retrieves additional scripts from a content delivery network and communicates with a smart contract on Ethereum’s Sepolia testnet. The contract then supplies a domain for the final skimmer delivery.

This approach, termed EtherHiding, signifies a novel use of public blockchain as a directory for attack infrastructure, complicating detection and prevention efforts. The attackers can seamlessly update the domain used without altering the compromised site’s code, thereby evading simple blocking mechanisms.

Mitigation and Consumer Safety

To mitigate such threats, e-commerce operators are urged to scrutinize server-side modifications, check plugins and admin accounts, and inspect all scripts loaded during the checkout process. Comparing checkout behaviors while logged out and monitoring requests to unfamiliar domains are also recommended practices.

Consumers, on the other hand, should remain vigilant. Successful transactions do not guarantee checkout safety. Those who suspect their card information may have been compromised should immediately contact their card issuer, watch for unauthorized charges, and replace their card if necessary.

The HexMage campaign underscores the vulnerability of online stores and the sophisticated measures attackers employ by using resilient blockchain technology as a cover. Continuous monitoring and proactive security measures are essential for protecting e-commerce platforms and their users.

Cyber Security News Tags:Blockchain, Confiant, credit card theft, Cybersecurity, e-commerce, Ethereum, HexMage, Magecart, Sepolia, smart contracts

Post navigation

Previous Post: Hackers Target Critical Ruby on Rails Flaw for Remote Code Execution
Next Post: ValleyRAT Malware Concealed in Trusted Adware

Related Posts

Anthropic Unveils Claude AI Models for Enhanced Research Anthropic Unveils Claude AI Models for Enhanced Research Cyber Security News
New Inboxfuscation Tool That Bypasses Microsoft Exchange Inbox Rules and Evade Detection New Inboxfuscation Tool That Bypasses Microsoft Exchange Inbox Rules and Evade Detection Cyber Security News
Top 10 Best Data Security Companies in 2026 Top 10 Best Data Security Companies in 2026 Cyber Security News
Microsoft’s Copilot Disclaimer Sparks Security Debate Microsoft’s Copilot Disclaimer Sparks Security Debate Cyber Security News
Microsoft Teams Exploited in SynkLoader Cyber Attacks Microsoft Teams Exploited in SynkLoader Cyber Attacks Cyber Security News
New PhantomCaptcha RAT Weaponized PDFs to Deliver Malware Using ‘ClickFix’-Style Cloudflare Captcha Pages New PhantomCaptcha RAT Weaponized PDFs to Deliver Malware Using ‘ClickFix’-Style Cloudflare Captcha Pages Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks
  • Russian Enterprises Face Threats from Cyber Groups
  • TP-Link Camera Vulnerabilities Threaten User Privacy
  • AI-Driven Data Breach Notified to Spanish Authorities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks
  • Russian Enterprises Face Threats from Cyber Groups
  • TP-Link Camera Vulnerabilities Threaten User Privacy
  • AI-Driven Data Breach Notified to Spanish Authorities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark