Skip to main content
Sign in

MyAlgo

avoid.net/myalgo12/100·88% conf.
[AI-DRAFTED · AWAITING VERIFICATION][src:defillama]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·PiskFy…jsEZ

Summary

MyAlgo was a non-custodial web browser wallet for the Algorand blockchain, developed by Rand Labs. Between January and March 2023, a supply-chain attack via a compromised CDN (content delivery network) resulted in the theft of approximately $9.6 million in ALGO and USDC across at least five distinct attack waves. The wallet was officially shut down on January 30, 2024, following the incident and subsequent user attrition.

Connected Entities

1 entities
Organizations
MyAlgo
Relationships
  • + 3 more
Have evidence about MyAlgo?

Timeline(13 events)

16 February 2021

Rand Labs releases updated MyAlgo wallet with multisig support, establishing it as a primary Algorand wallet.

GlobeNewswire

21 January 2023

Malicious JavaScript worker uploaded to the CDN serving wallet.myalgo.com, beginning silent private key exfiltration from users who unlocked their wallets.

Quadriga Initiative case study

19 February 2023

First wave of active thefts begins; attackers use harvested credentials to drain approximately $7.2 million confirmed across 17 addresses.

D13.co preliminary advisory report

21 February 2023

First theft wave concludes. Total losses in this wave estimated at $9.2-9.6 million including 19.5M ALGO and 3.5M USDC. ZachXBT publicly quantifies stolen amounts.

CoinDesk

27 February 2023

MyAlgo issues public warning advising all mnemonic wallet users to immediately withdraw funds. New wallet version released, ending the CDN injection.

Decrypt

28 February 2023

CoinDesk publishes initial reporting. ChangeNOW freezes approximately $1.5 million in stolen funds transiting through its platform.

CoinDesk

5 March 2023

Second wave of thefts begins, targeting additional compromised credentials.

D13.co fifth wave data

6 March 2023

Algorand Foundation publicly acknowledges the exploit after approximately two weeks of silence. Algodex also reports its company wallet was infiltrated by a malicious actor (loss under $55,000). Lofty.ai reports $65,000 theft on Algorand.

CoinTelegraph

9 March 2023

Algorand Foundation CTO John Woods releases statement confirming the exploit is not caused by an underlying issue with the Algorand protocol or SDK.

Blockhead

17 March 2023

Fourth wave of thefts occurs.

D13.co fifth wave data

31 March 2023

Fifth and final documented wave of thefts occurs.

D13.co fifth wave data

April 2023

Exploit details — including the CDN injection date of January 21 — are publicly revealed. MyAlgo discloses preliminary findings identifying CDN MITM as the attack vector.

Quadriga Initiative case study

30 January 2024

MyAlgo wallet officially shut down and decommissioned. Platform no longer accessible for transaction signing.

Bitget Wallet guide
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 13 of 19 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 5/4/2026, 2:54:43 AM

last updated: 8/30/2026, 5:14:11 AM

avoid.net — verified advice for a post-truth world