MyAlgo hack — February 2023
Incident facts
| Date of incident | (approximate) |
|---|---|
| Publicly disclosed | February 27, 2023 |
| Target type | Wallet software or provider |
| Loss | $9,200,000Published estimates range $9,200,000 to $9,600,000Price at time of incident |
| Method | Supply chain or frontend compromiseMalicious JavaScript served to users through MyAlgo's content delivery network, sitting between wallet.myalgo.com and the browser, which harvested users' passwords and secret phrases and sent them to an attacker-controlled server. MyAlgo disclosed this man-in-the-middle mechanism in March 2023; Coinspect separately concluded the seed encryption itself was sound and that the attackers succeeded because they obtained users' passwords. |
| Chains | Other |
| Outcome | Unresolved |
What happened
MyAlgo was a browser-based wallet for the Algorand network. Between 19 and 21 February 2023 funds were drained from around 25 high-value accounts. On-chain investigator ZachXBT counted roughly 19.5 million ALGO and 3.5 million USDC and valued the theft at about $9.2 million; CoinDesk reported the same token amounts as $9.6 million. Both totals rest on the same on-chain count, so the lower figure is recorded with the higher kept as the bound.
An independent advisory published on 27 February by the researcher D13 confirmed at least $7.2 million taken from 17 addresses, with a further $1.4 million suspected across four more, and found the only common threads were desktop use of MyAlgo and a recent unlocking of the wallet. Coinspect, which worked with MyAlgo, ruled out any weakness in the encryption itself and concluded the attackers had obtained users' passwords and used them to decrypt stored seeds.
MyAlgo initially said it did not know the root cause and urged all users to move assets out of any wallet that had touched the platform. The Algorand Foundation issued a formal notice on 6 March repeating that instruction and stating the Algorand protocol itself had not been compromised.
In March 2023 MyAlgo published its own findings: attackers had abused its content delivery network to inject malicious code between the wallet.myalgo.com web app and the user, collecting passwords and secret phrases and sending them to attacker-controlled servers. MyAlgo said the attackers still held the stolen keys and could still move compromised funds. The exchange ChangeNOW froze about $1.5 million. No arrests have been reported.
Sources
- Algorand FoundationPrimary · retrieved 2026-08-01
- CointelegraphSecondary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- D13Secondary · retrieved 2026-08-01
- Coinspect SecuritySecondary · retrieved 2026-08-01
- CoinEdition via Investing.comSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "MyAlgo hack — February 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/myalgohttps://itokenly.com/hacks/myalgoPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.