# MyAlgo publishes attack incident report: Attackers use CDN API key to inject malicious code

By [BNBOP](https://paragraph.com/@bnbop) · 2023-04-23

---

MyAlgo tweeted a report on the previous attack. According to the report, attackers used possible CDN API keys to inject malicious code between the actual [http://wallet](http://wallet)(.)myalgo(.)com web page and users through a man-in-the-middle attack. It is unclear how the CDN API key was obtained, no evidence of an attack or vulnerability was found in the MyAlgo codebase, and there is no evidence that CDN user accounts were compromised. Additionally, there is no evidence in the CDN audit logs that a key was ever created to carry out this attack. The audit logs cover 18 months, while the affected account was created 19 months ago, but this account was not used until October 2022 (6 months ago). This adds a very low possibility that the logs are missing or that the API key was obtained 19 months ago, thus circumventing the logging. In addition, the attacker (for a specific version of MyAlgo) uploaded malicious code on January 21, and the attack continued until the release of the new version of MyAlgo in mid-February. Law enforcement and security professionals will continue to investigate and gather more information to help clarify the details of the attack. According to a previous tweet by ZachXBT, an on-chain data analyst, due to the attacks on the Algorand ecological wallet MyAlgo from February 19th to 21st, more than $9.2 million in assets on Algorand (19.5 million ALGOs, 3.5 million USDCs, etc.) steal.

---

*Originally published on [BNBOP](https://paragraph.com/@bnbop/myalgo-publishes-attack-incident-report-attackers-use-cdn-api-key-to-inject-malicious-code)*
