Crypto Security Incident

Incident Description: "Crypto Drainer" Malware
Website: FreedomVillage.org
Report Date: July 24, 2026
Incident Status: Remediation Complete

What Happened
Between June 11, 2026 and July 24, 2026, the Freedom Village of Orange County website (freedomvillage.org) was compromised by malicious software known as a "crypto drainer." This type of malware targets visitors who have cryptocurrency wallet software (such as MetaMask or Coinbase Wallet) installed in their web browser via a browser extension. When such a visitor lands on an infected site, the malware attempts to trick them into connecting their wallet and approving a transaction that would transfer their funds to the attacker.

The malware was completely invisible to the site's administrators and staff, as it was specifically designed to hide itself from logged-in administrators.  The malicious code was detected through a code review, and was promptly addressed and fully remediated the same day it was discovered.

The following steps were taken for remediation:

  • Removed all malicious files from the server.
  • Cleaned all malicious entries from the database.
  • Deployed a kill switch file that neutralizes the malware in visitor browsers that may have cached it.
  • Purged the Cloudflare cache so clean pages are served immediately.
  • Reestablished all administrator accounts, with enforced 2FA (Two-Factor Authentication.)
  • Published a disclosure of the incident on the website.

Was Anyone Harmed?
We have no evidence that any website visitor's finances were compromised.  We investigated the attacker's cryptocurrency wallet and the smart contract used to operate the malware. We found no evidence of successful fund transfers attributable to Freedom Village visitors. The attacker's wallet showed only $25.41 in value — consistent with a low-yield or unsuccessful operation against this particular site. However, we cannot say with absolute certainty that no visitor was ever affected. A visitor with a cryptocurrency wallet who approved a connection prompt would not leave any record on our server. However, the evidence strongly points to no meaningful victim impact.

What Should I Do?
Impacted visitors would need to meet the all of the following criteria:

  • You visited the FreedomVillage.org website between June 11, 2026 and July 24, 2026, AND…
  • You have a cryptocurrency wallet, AND…
  • You access your wallet through a browser extension, AND…
  • You responded to a fraudulent request to "connect your wallet," AND...
  • You "approved" a malicious transaction

If you meet all of these criteria, and you suspect you may be a victim of this scam, time matters.

  • Disconnect from the suspicious site.
  • Move any remaining assets to a new, safe wallet if possible.
  • Revoke the malicious token approvals before the attacker uses them.
  • Never enter your recovery phrase into any website claiming to "recover" your wallet—those are almost always additional scams.

The key takeaway is that most crypto drainers don't "hack" wallets in the traditional sense. Instead, they trick users into authorizing transactions or permissions that allow the attacker to legally move assets according to the blockchain's rules.