An unauthorized promotion for a purported “LEGO Coin” appeared on LEGO.com on October 5, 2024, using the toy company’s brand and official website to direct visitors toward an external cryptocurrency transaction page.
LEGO Group confirmed that the banner was unauthorized, was removed quickly and did not represent a genuine company token launch. The incident mattered beyond the small token involved: attackers had placed a cryptocurrency solicitation inside a globally recognized company’s trusted digital property, bypassing the skepticism that an unfamiliar website would ordinarily trigger.
The surviving evidence does not reveal how the unauthorized content was installed. Reports widely described the incident as a website hack, but LEGO declined to disclose the identified cause or its remediation measures. The verified claim is therefore that LEGO.com displayed unauthorized promotional content—not that a particular vulnerability, employee account or infrastructure provider was responsible.
A brief but authentic-looking promotion
Screenshots and contemporaneous eyewitness records showed a homepage banner illustrated with gold-colored coins and LEGO branding. The message falsely presented “LEGO Coin” as an official release and promised unspecified rewards. A purchase button reportedly led visitors to a page where a token could be acquired using ether.
A moderator of the LEGO community on Reddit recorded that the altered page was noticed at approximately 9 p.m. Eastern Daylight Time on October 4 and appeared restored by approximately 10:15 p.m. That corresponds to roughly 1:00 a.m. through 2:15 a.m. UTC on October 5. The approximately 75-minute duration is an eyewitness estimate, not a server-log measurement supplied by LEGO.
Engadget published LEGO’s response on October 5. The company dated the incident October 5 while noting that it occurred during the evening of October 4 in the United States. LEGO said the unauthorized banner appeared only briefly, that the issue had been resolved and that customer accounts had not been compromised. It also said it had identified the cause and was implementing preventive measures, without explaining either.
BleepingComputer subsequently reported that the destination was a Uniswap interface rather than a wallet-draining imitation of one. That distinction limits what can be claimed. The available evidence supports an attempt to induce purchases of an unofficial token; it does not establish that merely opening the destination automatically transferred assets or exposed a visitor’s wallet credentials.
Brand authority became part of the attack
Anyone can create a token bearing a familiar name. What made the October 5 incident significant was the placement of the promotion on LEGO’s real website. A visitor did not first encounter the solicitation through an anonymous social account, unsolicited message or misspelled domain. The false claim appeared under the authority of a legitimate consumer brand.
That illustrates a recurring digital-asset security problem: authenticity depends on more than whether a token contract exists or whether a trading interface functions. A real smart contract can still be attached to a false issuer identity. Likewise, a legitimate decentralized exchange can execute trades involving a token promoted through deception.
The incident also separated website integrity from blockchain integrity. No reviewed source identified a failure in Ethereum or Uniswap’s protocol. The apparent security failure occurred in the channel used to persuade people that the token was legitimate. The blockchain could faithfully settle a transaction while the buyer’s premise—that LEGO endorsed the asset—remained false.
What the record could not establish
No authoritative event-day record quantified visitor exposure, token purchases, attacker proceeds or customer losses. Later reports offered small transaction estimates, but they did not provide a complete, reproducible market dataset linking individual trades to LEGO.com visitors. This reconstruction therefore makes no loss, volume, price or market-impact claim.
LEGO’s assurance about customer accounts was a contemporaneous company statement, not an independently published forensic report. As of October 5, the identities of those responsible, the access method and the full technical scope remained undisclosed. The defensible conclusion was narrow: an unauthorized cryptocurrency promotion briefly occupied LEGO’s official homepage, was removed, and exposed how control of a trusted web channel could manufacture apparent legitimacy for an unofficial token.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

