LEGO's website was hacked to promote a fake cryptocurrency, misleading users into purchasing scam tokens with Ethereum.
The company quickly removed the fraudulent banner and assured customers that no accounts were compromised and that preventive measures are in place.
This incident highlights a trend where scammers exploit trusted brands to deceive victims.
In June 2024, hackers similarly compromised the Ethereum Foundation’s email, targeting nearly 36,000 subscribers, while Metallica’s official X account was used to promote a scam token, generating about $10 million in trades.
Crypto scams have grown increasingly sophisticated, with losses estimated at $1.2 billion in 2024. While LEGO has not provided specifics on how the breach occurred, it’s likely that organized groups were involved, potentially taking advantage of a misconfigured web application firewall or external service vulnerabilities.
The attack demonstrates the ongoing risks even major brands face, leaving customers concerned about the extent of the breach and the measures taken to prevent future incidents.
The U.S. Department of Justice has sentenced Dwayne Golden, 57, of Pennsylvania to 97 months in prison for orchestrating a fraudulent crypto investment scheme that stole over $40 million from investors.
The first half of 2025 has become the most damaging six-month period in crypto history, with over $2.1 billion stolen across 75+ separate incidents, according to new data.
A new breed of cyber-attack is sweeping through crypto media, exploiting site pop-ups and wallet-connect prompts instead of smart-contract bugs.
CoinMarketCap, one of the most widely used crypto data tracking platforms, is reportedly facing a front-end security breach, with multiple users encountering a suspicious prompt to verify their wallets.