Attackers manipulated internet routing on April 24, 2018, redirecting some requests for MyEtherWallet.com to a phishing site capable of capturing the credentials users employed to access Ethereum wallets. Contemporaneous technical analysis traced the diversion to unauthorized announcements covering portions of Amazon’s Route 53 address space.
The incident mattered beyond the approximately 215 ether that contemporaneous security reporting attributed to the theft. It demonstrated that a cryptocurrency service could retain control of its application and domain settings while users were still exposed through weaknesses in the internet infrastructure connecting them to it.
A route to the wrong server
Cloudflare’s April 24 analysis recorded five more-specific route announcements affecting Amazon address ranges used by Route 53. The announcements began at approximately 11:05 UTC and ended at 13:03 UTC, creating an exposure window of just under two hours. They originated from AS10297, associated with Ohio network provider eNet, according to the routing record cited by Cloudflare.
Under the Border Gateway Protocol, networks advertise the internet addresses they can reach. Routers generally favor a more-specific route, so the unauthorized announcements could pull traffic away from Amazon’s legitimate path. DNS resolvers following the diverted route received false answers for MyEtherWallet.com that pointed toward infrastructure associated with Russian networks.
Cloudflare reported that the malicious servers answered queries for MyEtherWallet.com rather than indiscriminately impersonating every Route 53 customer. That behavior indicates a targeted operation, although the public evidence available on April 24 did not identify the attackers or establish how AS10297 came to originate the routes.
The browser warning was the last barrier
The phishing server presented a self-signed TLS certificate. Visitors using HTTPS therefore encountered a certificate warning before reaching the counterfeit wallet interface. Cloudflare’s analysis said a user had to proceed through that warning for the impersonation to work.
MyEtherWallet warned users during the incident that some DNS servers had been hijacked and were directing visitors to a phishing site. The service described the problem as external to its own systems while it investigated the affected infrastructure. Subsequent technical reporting supported the central distinction: this was not evidence that attackers had changed Ethereum’s ledger or exploited a MyEtherWallet smart contract.
MyEtherWallet was an open-source, client-side interface through which users could access wallets and initiate Ethereum transactions. That design did not make funds recoverable if a user disclosed a private key to an impostor. Once the phishing page obtained usable wallet credentials, the attacker could submit valid transfers to Ethereum, where the resulting transactions were not reversible by the interface provider.
Contemporaneous reporting counted approximately 215 ETH taken during the episode and valued it near $160,000 at transaction-time prices. The ether total is better supported than the dollar conversion because ETH traded continuously across venues and had no single official price.
A rising market met an infrastructure warning
Kraken’s April 24 daily market report listed ETH at $703.10, up 10.5% over the report’s daily window, with approximately $129 million traded in its ETH markets. Multiplying that venue-specific reference price by 215 ETH produces about $151,167, illustrating how the reported dollar loss varied with price source and observation time. Kraken’s figures were an exchange snapshot, not a consolidated global close, while the reported $160,000 estimate reflected prices nearer the transfers.
The episode showed that control of cryptographic keys was only one part of wallet security. Domain resolution, inter-network routing and certificate validation remained conventional trust layers between users and a browser-based cryptocurrency interface.
Later-confirmed context
On June 4, 2018, MyEtherWallet confirmed that a BGP hijack against Amazon DNS infrastructure had routed visitors to a phishing copy of its site. It also disclosed a planned migration of its DNS service to Cloudflare and additional certificate controls. Those remediation details were not available on April 24 and are included only as later confirmation of the incident’s mechanism.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

