← Moonshot (DEX Screener)

2026 Moonshot — phishing campaign; suspected user-email exposure under investigation (Jul)

2026 Unknown records affected Share on X

Data compromised

Suspected exposure of user email addresses (under investigation). Phishing emails used subject lines such as "Review recent activity" / "View Recent Activity"; Moonshot said no signs of compromised accounts at disclosure

Technical writeup

Verified platform warning — reported July 20, 2026. Moonshot, the token-launch platform operated by DEX Screener, posted an official alert that some users received phishing emails with subjects such as "Review recent activity" or "View Recent Activity" that did not originate from Moonshot. The company said it found no signs of compromised accounts and was investigating how attackers obtained recipient addresses. Multiple users on X reported receiving both legitimate login verification messages from [email protected] and separate phishing mail from unrelated senders (including third-party domains such as updox.com), raising concerns that Moonshot user email addresses may have been exposed through a separate leak or list aggregation. Moonshot advised users to delete the messages, avoid links, contact in-app support if they entered codes, and access the service only through the official app. No attested victim count or confirmed database exfiltration had been published at indexing time; BreachHistory retains recordsAffected 0 pending a company or forensic total.

Root cause

Third-party phishing emails targeting Moonshot users; company investigating whether user email addresses were exposed—no account compromise confirmed at disclosure

References