StopAndProtect Malware Campaign Weaponizes 2,000 WordPress Sites Against Crypto Wallets
Roughly 2,000 compromised WordPress installations are now serving as criminal infrastructure to steal cryptocurrency wallet files and deploy ransomware. The coordinated operation, tracked as "StopAndProtect," silently delivers malware to site visitors, then hunts for locally stored wallet files.
StopAndProtect Malware Campaign Weaponizes 2,000 WordPress Sites Against Crypto Wallets
Roughly 2,000 compromised WordPress installations are now serving as criminal infrastructure to steal cryptocurrency wallet files and deploy ransomware. The coordinated operation, tracked as "StopAndProtect," silently delivers malware to visitors of hacked sites, then hunts for locally stored wallet files and exfiltrates them to attacker-controlled servers. Ransomware deployment runs alongside the theft, giving operators dual revenue: stolen crypto assets and ransom payments from encrypted files.
WordPress powers 43% of all websites globally, making it an attractive target for attackers seeking scale. The platform's sprawling plugin ecosystem creates a wide attack surface. Site owners who delay patching or run outdated plugins hand adversaries ready-made footholds. Once compromised, a single site can serve malware to every visitor, regardless of whether those visitors have any connection to crypto. That's the leverage StopAndProtect exploits: the victim doesn't need to visit a crypto-specific site, only an infected one.
WordPress-based malware campaigns have targeted crypto users for several years. Notable waves followed the 2021 Elementor plugin vulnerability and the 2022 WP Super Cache exploitation, each exposing thousands of sites. What distinguishes StopAndProtect is its explicit focus on wallet file theft at scale, combining that objective with ransomware in a single coordinated campaign rather than running them as separate operations.
"The StopAndProtect operation used compromised WordPress websites to spread malware, steal crypto wallet files, and deploy ransomware."
The attack primarily threatens users who store wallet files or seed phrases on internet-connected machines. Hardware wallet users and those maintaining strict air-gap practices face no exposure from this vector. But retail crypto holders who keep software wallets on general-purpose computers they also use for everyday browsing are at real risk. A single visit to an infected news site, blog, or small business page is enough.
Defenders have straightforward mitigations that require discipline. WordPress site owners need to apply security patches promptly, audit installed plugins, enforce strong authentication, and run integrity monitoring. Crypto holders should move meaningful balances off software wallets onto hardware devices, avoid storing seed phrases in plaintext on networked machines, and treat any unexpected browser behavior as a potential indicator of compromise.
The incident raises a structural question about the crypto industry's security posture. Blockchain protocols themselves are not the vulnerability. The weak link is the surrounding infrastructure: the websites, operating systems, and user habits that sit between a person and their on-chain assets. As on-chain security has improved, attackers have increasingly shifted focus to this softer perimeter. StopAndProtect exemplifies that trend. Two thousand compromised sites represents a professional criminal operation running at meaningful scale, and the combination of wallet theft with ransomware suggests operators sophisticated enough to maximize revenue from each infected machine.
The 2,000-site figure represents known compromised infrastructure. The actual distribution footprint, measured by how many users those sites collectively serve, is considerably larger.





