Features

StopAndProtect Ransomware: How 2,000 WordPress Sites Are Being Used to Drain Your Crypto Wallet

CryptoRover

Check Point researchers just dropped a bombshell: nearly 2,000 WordPress sites have been weaponized to steal crypto recovery phrases. The attack, dubbed ‘StopAndProtect,’ has been active since May 2024, infecting over 6,000 IPs across the US, Russia, and India. The kill chain is deceptively simple — a fake CAPTCHA prompts Windows users to paste a PowerShell command that downloads malware, steals credentials, and encrypts files. But the real prize? Your wallet seed phrase.

This isn’t a zero-day exploit targeting smart contracts. It’s a social engineering masterpiece that exploits the weakest link: human trust. Tracing the code back to the genesis block of this attack, we see a mature operation: compromised WordPress sites serve as C2 infrastructure, hosting malicious payloads, storing stolen data, and issuing commands. The scale is staggering — over 31,000 screenshots and 700+ compressed files were captured from victims.

Here’s how the attack chain unfolds: 1. WordPress compromise: Attackers likely exploit known plugin vulnerabilities (no zero-days needed — just good old-fashioned poor maintenance). 2. Fake CAPTCHA: When a user lands on the infected site, a CAPTCHA appears, asking them to press ‘Win + R’ and paste a command. 3. PowerShell payload: The command downloads an executable that steals browser cookies, saved credentials, and — critically — scans for cryptocurrency wallet recovery phrases. 4. Ransomware + lateral spread: The malware encrypts local files, then spreads via network shares and USB drives.

Based on my audit experience, this is the most dangerous crypto attack vector today. Unlike DeFi hacks that get patched, this exploits the seed phrase — the single point of failure for every self-custodied wallet. Once leaked, the attacker can drain all assets without any on-chain signature. The irony? Check Point researchers believe the attackers accidentally infected their own environment, which is why they captured so much internal data.

Sprinting through the noise to find the signal: The real threat isn’t the ransomware — it’s the silent exfiltration of recovery phrases. Most victims won’t even know they’re compromised until their wallets are drained weeks later. The attackers are methodical: they collect screenshots of desktops, browser history, and any file containing ‘seed,’ ‘backup,’ or ‘wallet.’

Contrarian angle: The crypto community obsesses over smart contract audits, but this attack proves that the weakest link is the human operating system. We’re conditioned to trust CAPTCHAs — they’re supposed to protect us from bots. Here, the CAPTCHA itself is the malware vector. The lesson is counterintuitive: never execute a command you didn’t initiate, even if it comes from a legitimate-looking website.

Reading the tape before the chart confirms it: This attack pattern will be replicated. WordPress is just the first wave; next could be compromised e-commerce sites, forums, or even crypto dashboard tools. The security industry needs to pivot from ‘don’t click links’ to ‘don’t paste code you don’t understand.’

The takeaway? The most dangerous exploit isn’t on the blockchain — it’s between the chair and the keyboard. Until users treat every command prompt like a loaded weapon, attacks like StopAndProtect will keep evolving. The question is: will you be the next target?