Cryptocurrency exchange EtherDelta gets hacked and replaced by a fake site that steals your money

Do not use EtherDelta until further notice.
 By 
Stan Schroeder
 on 
Cryptocurrency exchange EtherDelta gets hacked and replaced by a fake site that steals your money
Credit: Shutterstock / JoshuaDaniel

Popular cryptocurrency exchange EtherDelta got hacked in spectacular fashion Wednesday, with many users unknowingly sending their tokens to the hacker instead of the exchange.

At least 308 ETH ($266,789) were stolen, as well as a large number of tokens potentially worth hundreds of thousands of dollars.

EtherDelta is a decentralized exchange which lists nearly all Ethereum-based tokens in existence. It doesn't have a huge volume compared to larger exchanges but it's an important first step for traders after a new token gets generated in an ICO (initial coin offering).

Apparently, the smart contracts that govern EtherDelta's behavior weren't compromised in the attack. Instead, the attacker managed to take over EtherDelta's DNS server and serve a fake version of the site to visitors.

This is far more dangerous than the common phishing attack in which a fake site sets up a domain name similar to the real one (such as etherrddeltta.com). Users who visited the actual EtherDelta site in the afternoon (ET time) Wednesday were served a partially functional but still quite convincing version of the site. The attack appears to have been mitigated within a few hours, and the proper EtherDelta site restored, but anyone who interacted with the fake site may have sent ether or other tokens to the hacker.

EtherDelta confirmed the attack on Twitter and advised all users not to use the site. At the time of writing, they haven't lifted the warning, so EtherDelta should still be considered unsafe to use.

Thanks to the public nature of Ethereum's blockchain, you can see how the funds were moved in and out of the hacker's probable address here. Ether and tokens flowed in from 1:40 p.m. ET up until roughly 8 p.m. ET; the attacker moved the bulk of the funds to other addresses at roughly 1:30 a.m. ET Thursday.

There are various ways to interact with EtherDelta; either through the Ledger Nano S hardware wallet (the safest way), through a software wallet such as Metamask (a little less safe), or by just entering your private key into the site itself (the least safe way). It's difficult to say whether private keys were exposed to the hack, but it's possible.

Users would probably do well to move any funds out of the wallets used for interacting with EtherDelta into new, secure wallets. You can check the state of the wallets you used with EtherDelta over at deltabalances.github.io.

This hack is another warning of the dangers when dealing with cryptocurrencies. While EtherDelta is supposed to be decentralized, it still has a central point of entry -- its website -- which, when compromised, can result in catastrophe.

Stan Schroeder
Stan Schroeder
Senior Editor

Stan is a Senior Editor at Mashable, where he has worked since 2007. He's got more battery-powered gadgets and band t-shirts than you. He writes about the next groundbreaking thing. Typically, this is a phone, a coin, or a car. His ultimate goal is to know something about everything.

Mashable Potato

Recommended For You

The European Commission got hacked for the second time this year
Europe flag

AdultFriendFinder profiles: 3 tips to sort legit from fake
By Jack Dawes
AFF logo on phone


The Epstein Files: Read Epstein's emails as if you hacked into his Gmail with Jmail
Jmail World

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

NYT Connections hints today: Clues, answers for April 4, 2026
Connections game on a smartphone

Google launches Gemma 4, a new open-source model: How to try it
Google Gemma

Wordle today: Answer, hints for April 4, 2026
Wordle game on a smartphone
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!