Ethereum Blockchain Exploited in Global Card-Skimming Campaign
Cybercriminals have been exploiting Ethereum blockchain technology to steal payment-card details from online shoppers, according to researchers. The campaign, known as HexMage, compromises legitimate e-commerce websites and injects malicious JavaScript into checkout pages.
The attackers use a technique called EtherHiding, which stores or retrieves attack information through blockchain smart contracts. This makes it difficult for defenders to remove the malicious data from the Ethereum Sepolia testnet contract.
Researchers have identified more than 40 affected merchant websites across at least 15 countries since April 2026. The compromised stores use various e-commerce platforms, including WooCommerce, PrestaShop, Magento, and standard WordPress installations.