Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·PiskFy…jsEZSummary
MyAlgo was a non-custodial web browser wallet for the Algorand blockchain, developed by Rand Labs. Between January and March 2023, a supply-chain attack via a compromised CDN (content delivery network) resulted in the theft of approximately $9.6 million in ALGO and USDC across at least five distinct attack waves. The wallet was officially shut down on January 30, 2024, following the incident and subsequent user attrition.
Connected Entities
1 entities- + 3 more
Timeline(13 events)
16 February 2021
Rand Labs releases updated MyAlgo wallet with multisig support, establishing it as a primary Algorand wallet.
GlobeNewswire21 January 2023
Malicious JavaScript worker uploaded to the CDN serving wallet.myalgo.com, beginning silent private key exfiltration from users who unlocked their wallets.
Quadriga Initiative case study19 February 2023
First wave of active thefts begins; attackers use harvested credentials to drain approximately $7.2 million confirmed across 17 addresses.
D13.co preliminary advisory report21 February 2023
First theft wave concludes. Total losses in this wave estimated at $9.2-9.6 million including 19.5M ALGO and 3.5M USDC. ZachXBT publicly quantifies stolen amounts.
CoinDesk27 February 2023
MyAlgo issues public warning advising all mnemonic wallet users to immediately withdraw funds. New wallet version released, ending the CDN injection.
Decrypt28 February 2023
CoinDesk publishes initial reporting. ChangeNOW freezes approximately $1.5 million in stolen funds transiting through its platform.
CoinDesk5 March 2023
Second wave of thefts begins, targeting additional compromised credentials.
D13.co fifth wave data6 March 2023
Algorand Foundation publicly acknowledges the exploit after approximately two weeks of silence. Algodex also reports its company wallet was infiltrated by a malicious actor (loss under $55,000). Lofty.ai reports $65,000 theft on Algorand.
CoinTelegraph9 March 2023
Algorand Foundation CTO John Woods releases statement confirming the exploit is not caused by an underlying issue with the Algorand protocol or SDK.
BlockheadApril 2023
Exploit details — including the CDN injection date of January 21 — are publicly revealed. MyAlgo discloses preliminary findings identifying CDN MITM as the attack vector.
Quadriga Initiative case study30 January 2024
MyAlgo wallet officially shut down and decommissioned. Platform no longer accessible for transaction signing.
Bitget Wallet guideDecision Log
- hash: D2qQi3gakPoV8fEB78TtLaEfyY2g4Lh4yYZzuZ8PViuf
This investigation is cryptographically anchored to the Solana blockchain (1 event). 13 of 19 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:43 AM
last updated: 8/30/2026, 5:14:11 AM
avoid.net — verified advice for a post-truth world