📈 Get daily crypto insights that make you smarter about your money

ONNX MFA Bypass and Political Phishing Campaigns Target Crypto Users as Dual Security Threat Escalates

The cryptocurrency ecosystem faced a dual-pronged security crisis on June 19, 2024, as politically motivated phishing campaigns targeting Trump supporters and a newly disclosed MFA bypass technique exposed the widening attack surface facing digital asset holders. With Bitcoin trading at approximately $64,960 and Ethereum at $3,559, the sheer value locked in crypto wallets makes every new vulnerability a high-stakes threat.

The Exploit Mechanics

Security researchers at EclecticIQ uncovered a sophisticated campaign leveraging the ONNX protocol to bypass multi-factor authentication on Microsoft 365 accounts. The attack vector exploits a weakness in the authentication flow that allows threat actors to intercept and relay MFA tokens in real time, effectively neutralizing what most users consider their primary line of defense against unauthorized access.

Simultaneously, cybersecurity firm Netcraft documented a surge in crypto donation scams capitalizing on the Trump campaign’s announcement that it would accept cryptocurrency donations. Fraudsters registered misspelled domains such as “donalbjtrump[.]com” and “doonaldjtrump[.]com” within hours of the campaign’s crypto announcement, creating near-identical replicas of the official donation portal.

These fake sites integrated lookalike payment processors mimicking Coinbase, Coingate, Plisio, and Oxapay, making it exceptionally difficult for donors to distinguish legitimate from fraudulent transactions. The attackers leveraged AI tools to generate convincing website copy and phishing emails, amplifying the scale and sophistication of the campaign beyond what traditional scam operations could achieve.

Affected Systems

The ONNX MFA bypass primarily targets enterprise environments using Microsoft 365 for email and document management, which includes a significant portion of crypto companies, exchanges, and blockchain startups. Once an attacker gains access to a corporate email account, they can intercept password reset links, two-factor authentication codes, and sensitive wallet information.

The Trump campaign donation scams affect individual crypto users across all major networks, including Bitcoin, Ethereum, and various ERC-20 tokens. Netcraft reported that the fraudulent domains began appearing immediately after the campaign’s crypto donation announcement, with the volume of scam sites intensifying following Trump’s federal conviction on May 31, when the campaign raised over $50 million in 24 hours.

The cross-section of these two threats is particularly concerning: attackers who successfully bypass MFA on corporate accounts could gain access to internal systems at crypto firms, while simultaneously, retail users face increasingly convincing phishing sites that leverage real-world political events as social engineering bait.

The Mitigation Strategy

For the ONNX MFA bypass, organizations should migrate from SMS-based and basic push notification authentication to hardware security keys (FIDO2/WebAuthn). These tokens are resistant to relay attacks because they cryptographically bind to the specific domain being authenticated, making interception and replay impossible.

Netcraft recommended that political campaigns and organizations accepting crypto donations implement domain monitoring services that flag suspicious registrations in real time. Additionally, users should verify donation URLs directly from official campaign channels rather than clicking links in emails or text messages.

Exchange operators and wallet providers should consider implementing address allowlisting for high-value transactions, requiring users to pre-register withdrawal addresses through a separate verification process. This creates an additional layer of protection even if an attacker compromises login credentials.

Lessons Learned

The convergence of political events and cryptocurrency creates a unique threat landscape where attackers exploit heightened emotions and urgency to bypass rational security thinking. The Trump campaign scam demonstrates that any major public announcement involving crypto can trigger an immediate wave of fraudulent activity.

The ONNX MFA bypass reinforces that traditional multi-factor authentication is no longer sufficient as a standalone security measure. Organizations handling significant cryptocurrency assets must adopt phishing-resistant authentication methods and implement zero-trust architecture principles.

Perhaps most critically, the use of AI by threat actors to generate convincing phishing content signals a fundamental shift in the economics of social engineering attacks. What previously required skilled human operators can now be automated at scale, lowering the barrier to entry for sophisticated crypto theft.

User Action Required

Individual crypto holders should immediately audit their authentication methods, switching to hardware security keys where possible. Before making any crypto donation, verify the recipient address through multiple independent sources. Enable withdrawal address allowlisting on all exchange accounts and consider using a dedicated hardware wallet for long-term storage. Organizations should conduct an immediate review of their MFA implementation, prioritizing migration to FIDO2-compatible solutions and implementing real-time domain monitoring for their brand assets.

This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research before making investment or security decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

27 thoughts on “ONNX MFA Bypass and Political Phishing Campaigns Target Crypto Users as Dual Security Threat Escalates”

  1. Bianca R. no chargebacks is exactly why crypto holders are the premium phishing target. banks can reverse fraudulent wires. blockchain cant

  2. MFA bypass via ONNX protocol is terrifying. most people think 2FA makes them bulletproof and it just… doesnt anymore

    1. hardware keys via webauthn are the only thing that stops relay attacks. app-based 2FA and SMS are basically decoration at this point

      1. keybase_ghost_

        epoch_timer webauthn with device binding stops relay attacks cold. app based 2FA is security theater against adversary in the middle toolkits

    2. phishspotter ONNX relay attacks mean even hardware keys can be intercepted if the session token gets hijacked. 2FA is speed bumps not walls at this point

    3. phishspotter ONNX relay attacks making hardware keys useless against session interception is the scariest part. people think webauthn makes them bulletproof and the session cookie vulnerability says otherwise

  3. The Trump donation scam domains were registered within hours. these crews move faster than most security teams can respond

      1. dontalbjtrump dot com is almost comedic but conversion rates on typo domains during breaking news events are genuinely terrifying. 2-3% is enough to fund a cartel

      2. margin_call_mike

        dontalbjtrump[.]com converting at 2-3% during breaking news is the business model. these phishing crews run A/B tested landing pages with urgency timers. they are not hackers they are direct response marketers

    1. scam domain registration within hours of an announcement is standard now. the 2024 election cycle had fake donation sites for both sides running within minutes

    2. Kurt N. hours not days. the trump donation announcement went viral and scammers had fake domains up before most legitimate news outlets covered it

  4. the overlap between political phishing and crypto targeting is growing because crypto wallets dont have chargebacks. once the funds leave, theyre gone

  5. BTC at $65K and ETH at $3.5K means every wallet is a high value target. the ONNX MFA bypass combined with political phishing is a perfect storm for crypto holders

    1. BTC at $65K means the average active wallet holds enough to make phishing profitable. the incentive to build sophisticated attacks scales with crypto valuations

      1. wallet_guard_42

        scammers moved faster than the news. had fake donation sites up before most legitimate outlets even covered the announcement. that’s the new normal

    2. MFA bypass via ONNX protocol shows that even hardware keys can be compromised if the session gets hijacked. 2FA is just speed bumps, not walls anymore

      1. María G. raises the right point about hardware keys. the ONNX relay bypass works because most MFA implementations treat the session cookie as implicitly trusted after the second factor is verified. if the relay intercepts the session token after MFA approval the hardware key becomes useless. the fix is binding the session to the specific hardware key not just to a successful auth event

        1. session_hijack_

          Catarina F. nailed the real issue. MFA gets verified but the session cookie becomes the weak link. binding the session to the hardware key is the only real fix

          1. session_hijack_ hardware key bound session is the right answer. webauthn with device attestation makes relay attacks nearly impossible. app based 2FA is held together with duct tape

          2. social_eng_survivor

            session_hijack_ the ONNX relay attack works because MFA implementations treat session cookies as implicitly trusted after verification. hardware keys become useless if the session token itself is intercepted post-auth

  6. crypto holders are the ideal phishing target because transactions are irreversible. bank fraud victims can file chargebacks but once BTC leaves your wallet the money is gone permanently. the ONNX bypass combined with political urgency creates the perfect exploitation window

    1. Ivan M. the irreversible transaction angle is what makes crypto the premium phishing target. banks can reverse wires. once BTC leaves that wallet its gone and scammers know the recovery window is zero

  7. crypto_analyst_99

    the political phishing angle is brutal. when Trump announced crypto donations, fake domains appeared within minutes. this is why hardware keys are non-negotiable for serious crypto holders

  8. poli_phish_track

    the speed of domain registration for political phishing is what makes this so dangerous. registrars need to implement cooling off periods for domains that match typos of major campaign sites. the current response time gap between scam domain creation and takedown requests is measured in weeks

    1. the typo domain registration speed is what makes political phishing lethal. registrars need mandatory cooling periods for domains matching typos of major campaign or crypto sites. the current gap between creation and takedown is measured in weeks

  9. Kurt N. 2-3% conversion on typo domains during breaking news is enough to fund entire phishing operations. the scammers are running this as a business with A/B tested landing pages and urgency triggers

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$65,073.00+0.2%ETH$1,922.23+0.2%SOL$76.59+1.5%BNB$605.94+1.7%XRP$1.04-0.2%ADA$0.1974-1.2%DOGE$0.0703-0.3%DOT$0.8083-0.8%AVAX$6.48-0.7%LINK$8.30-0.2%UNI$4.01+1.3%ATOM$1.37-1.8%LTC$46.22+1.4%ARB$0.0777-2.4%NEAR$1.62+1.0%FIL$0.7102-0.6%SUI$0.6950+0.4%BTC$65,073.00+0.2%ETH$1,922.23+0.2%SOL$76.59+1.5%BNB$605.94+1.7%XRP$1.04-0.2%ADA$0.1974-1.2%DOGE$0.0703-0.3%DOT$0.8083-0.8%AVAX$6.48-0.7%LINK$8.30-0.2%UNI$4.01+1.3%ATOM$1.37-1.8%LTC$46.22+1.4%ARB$0.0777-2.4%NEAR$1.62+1.0%FIL$0.7102-0.6%SUI$0.6950+0.4%
Scroll to Top