A campaign dubbed StopAndProtect turned compromised WordPress installations into infrastructure for wallet-draining attacks.
Nearly 2,000 WordPress websites have been hacked and converted into infrastructure supporting a cryptocurrency theft operation, according to security reporting. The campaign has been described using the name StopAndProtect. Researchers say the compromised sites were used as a base for stealing crypto wallets from unsuspecting visitors or users.
WordPress powers a large share of websites globally, making it a frequent target for attackers seeking scale. A single vulnerability in a popular plugin or theme can potentially be exploited across thousands of installations. That scale advantage appears central to how this operation reached nearly 2,000 sites.
Details on the precise technical method used to hijack the wallets have not been fully disclosed in available reporting. Campaigns of this type commonly rely on injected malicious scripts, fake wallet connection prompts, or redirects to phishing pages designed to mimic legitimate crypto services. Compromised legitimate websites are often more effective for these schemes than freshly registered malicious domains, since they carry an existing reputation and can bypass some browser and security filters.
The reported scale, nearly 2,000 sites, suggests an automated or semi-automated approach to compromise. Attackers likely scanned for outdated plugins, themes, or WordPress core versions before gaining access. Once inside, they could plant scripts or redirect logic without necessarily altering a site's visible content, making detection harder for site owners.
Crypto-focused attacks on web infrastructure are not new, but the reported size of this operation stands out. Wallet-draining schemes have grown more common as more everyday internet users interact with crypto wallets through browser extensions and web-based interfaces. A compromised website can serve as an entry point for malicious code that later requests wallet permissions or signatures from a visitor.
The use of a named operation, StopAndProtect, in describing this campaign suggests researchers may be tracking it as a distinct, organized effort rather than a series of unrelated incidents. Reporting has not specified whether the name refers to the attacker group's own branding, a researcher-assigned label, or a defensive operation aimed at countering the threat.
Website operators are generally advised to keep WordPress core software, plugins, and themes updated to reduce exposure to known vulnerabilities. Users interacting with crypto wallets through browser extensions are also advised to verify site authenticity before approving any transaction or signature request, particularly on sites that may have been compromised without visible signs of tampering.
The direct financial impact of this campaign on cryptocurrency markets has not been quantified in available reporting. Wallet-draining incidents typically affect individual holders rather than broader market pricing, though large-scale campaigns can erode general trust in web-based wallet interactions.
Incidents involving compromised infrastructure at this scale may prompt renewed scrutiny of browser extension security and website vulnerability management across the crypto industry. Exchanges, wallet providers, and security firms often respond to such campaigns by issuing advisories or updating detection tools used to flag malicious scripts embedded in legitimate-looking sites.
As investigators continue examining the scope of the StopAndProtect campaign, the incident underscores how vulnerabilities in widely used web platforms can be leveraged against cryptocurrency users far beyond the original compromised sites.
Nearly 2,000 WordPress websites were reportedly hacked and used as infrastructure in a campaign designed to steal cryptocurrency wallets from users.
StopAndProtect is the name reportedly associated with this campaign, though it is not fully clear whether it refers to the attackers' operation or a tracking label used by researchers.
Specific technical details have not been disclosed, but campaigns of this kind typically exploit outdated plugins, themes, or core software across many sites at once.
Users should verify site authenticity before connecting wallets or approving transactions, since compromised legitimate sites can host malicious scripts without visible changes.
We measure how many people read this site. That is all it is used for — there is no ad network, no advertising cookie, and nothing sold to anyone. Decline and the site works exactly the same. What we collect