Skip to main content

GoDaddy employees used in crypto services attacks

 


San Francisco, Nov 22 (IANS): Fraudsters have used employees at Internet names and registrations management major GoDaddy to attack multiple cryptocurrency services over the past one week, said a report.

While GoDaddy acknowledged that "limited" number of GoDaddy employees fell for a social engineering scam, the company did not reveal how the employees were tricked by the fraudsters to make the unauthorised changes required for the attacks, KrebsOnSecurity reported on Saturday.

The attacks led to modifications of "a small number" of customer domain names, according to GoDaddy spokesperson Dan Race who said that the incident was still under investigation, the report noted.

The use of GoDaddy employees in the attacks came to light after cryptocurrency trading platform liquid.com last week reported a security incident that occurred on November 13.

"A domain hosting provider 'GoDaddy' that manages one of our core domain names incorrectly transferred control of the account and domain to a malicious actor," Liquid CEO Mike Kayamori said in a blog post.

"This gave the actor the ability to change DNS records and in turn, take control of a number of internal email accounts. 

In due course, the malicious actor was able to partially compromise our infrastructure, and gain access to document storage."

Liquid said that the malicious actor might have been able to obtain personal information from its user database. 

This may include data such as email, name, address and encrypted password.

"After detecting the intruder we intercepted and contained the attack," Kayamori said.

Several other cryptocurrency services subsequently targeted by the fraudsters, according to the KrebsOnSecurity report.

This type of "social engineering" are becoming increasingly common. Earlier this year, Twitter revealed a massive cryptocurrency hack that compromised several high-profile accounts.

Twitter said that the "social engineering" that occurred on July 15 targeted a small number of employees through a phone spear phishing attack.


Comments

Contact us

Name

Email *

Message *

Popular posts from this blog

For my haters

₿  This is for people who told me to not put my money in Bitcoin 10 years ago 😂 RIP doubters and haters. #Bitcoin 💀 pic.twitter.com/sbuDljJtMv — Carl ₿ MENGER ⚡️🇸🇻 (@CarlBMenger) May 13, 2025

Coinbase to Require Recipient Information for Crypto Transfers From Users in Canada, Singapore and Japan

  Customers in those countries who send crypto outside their Coinbase accounts must provide recipients’ names, addresses and in some cases, additional information, as of early April. Cryptocurrency exchange Coinbase Global (COIN) will soon require its customers in Canada, Japan and Singapore who send cryptocurrency to another financial institution or exchange to provide the name, address and in the case of Japan, the destination wallet of the recipient. Coinbase has been sending notices to its customers in those countries that the changes will take effect in early April in order to comply with local travel rules in those places. Coinbase didn't immediately respond to requests for additional comment on the moves, but confirmed that they were taking place. The move  does not seem to be going over well  with Coinbase customers in those countries, who value the anonymity of transactions using cryptocurrency. According to a  FAQ provided by Coinbase , for Canadian users, ...

Jupiter plugin on your site

 Jupiter launches Jupiter Plugin , a customizable plugin that doesn't require RPC. PANews reported on August 7th that Jupiter announced the launch of the Jupiter Plugin.  This is an open-source, lightweight, plug-and-play version of Jupiter that allows users to seamlessly integrate end-to-end swap functionality into their applications with minimal effort.  Users can deploy it by simply adding a few lines of code.  Seamless Integration Embed Jupiter's Swap functionality directly into your application without redirection.  Multiple display options: Choose between integrated, widget or modal display modes.  Customizable options: Configure the exchange form to suit your application needs.  No RPC: Plugins can be integrated without any RPC, Ultra is responsible for handling transaction sending, wallet balance and token information.  Ultra Mode: Access all Ultra Mode features. Enjoy!