THORSwap said a third-party customer support platform used by both THORSwap and Metro Exchange, Mava, was compromised at the domain registrar level on Sept. 28, allowing malicious code to be injected into a support widget on the site. According to the project, the code could trigger a fake WalletConnect prompt, steal seed phrases or keystore data entered by users, and replace deposit addresses used for Direct Swap transactions. The incident resulted in roughly $58,000 in losses. THORSwap said about $54,200 came from compromised wallets, while another $3,500 was tied to altered Direct Swap deposit addresses. It added that affected users in the Direct Swap portion have been fully reimbursed. The team said its servers and application code were not affected and that the website is now safe again. Users who interacted with the dApp between 01:50 and 03:40 on Sept. 29, imported a seed phrase, copied or scanned a Direct Swap deposit address, or connected to the malicious WalletConnect prompt were urged to move funds to a new wallet immediately and revoke existing token approvals.
THORSwap said in a post on X that Mava, a third-party customer support platform used by THORSwap and Metro Exchange, was hijacked at the domain registrar level on Sept. 28, leading to malicious code being injected into a support widget and losses of about $58,000.
According to THORSwap, the injected code could display a malicious WalletConnect prompt, steal seed phrases or keystore information entered on the website, and replace Direct Swap deposit addresses.
The project said total losses were about $58,000. Of that amount, roughly $54,200 came from compromised wallets, while $3,500 came from tampered Direct Swap transactions. THORSwap said affected users in the Direct Swap portion have been fully reimbursed.
THORSwap also said its servers and application code were not affected, and that the related website has now been restored to a safe state.
The team urged users to act immediately if they used the dApp between 01:50 and 03:40 on Sept. 29, imported a seed phrase, copied or scanned a Direct Swap deposit address, or connected to the malicious WalletConnect prompt. Those users were told to move assets to a new wallet and revoke existing token approvals.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.