Aerodrome Finance, the leading decentralized exchange on the Base network, confirmed it is investigating a suspected DNS hijacking attack that compromisedAerodrome Finance, the leading decentralized exchange on the Base network, confirmed it is investigating a suspected DNS hijacking attack that compromised

Base’s Top DEX Aerodrome Hit by a Suspected Frontend Security Breach

Aerodrome Finance, the leading decentralized exchange on the Base network, confirmed it is investigating a suspected DNS hijacking attack that compromised its centralized domains.

The protocol warned users to avoid accessing its primary .finance and .box domains and instead use two secure decentralized mirrors hosted on ENS infrastructure.

The attack unfolded rapidly, with affected users reporting malicious signature requests designed to drain multiple assets, including NFTs, ETH, and USDC, through unlimited approval prompts.

While the team maintains that all smart contracts remain secure, the frontend compromise exposed users to sophisticated phishing attempts that could have drained wallets for those who weren’t carefully monitoring transaction approvals.

DNS Hijacking Forces Emergency Protocol Lockdown

Aerodrome’s investigation began when the team detected unusual activity on its primary domain infrastructure approximately six hours before issuing public warnings.

The protocol immediately flagged its domain provider, Box Domains, as potentially compromised and urged the service to reach out urgently.

Within hours, the team confirmed that both centralized domains, .finance and .box, had been hijacked and remained under attacker control.

The protocol responded by shutting down access to all primary URLs while establishing two verified safe alternatives: aero.drome.eth.limo and aero.drome.eth.link.

These decentralized mirrors leverage the Ethereum Name Service, which operates independently of traditional DNS systems that are vulnerable to hijacking.

The team emphasized that smart contract security remained intact throughout the incident, containing the breach exclusively to frontend access points.

Sister protocol Velodrome faced similar threats, prompting its team to issue parallel warnings about domain security.

The coordinated nature of the warnings suggested that attackers may have systematically targeted Box Domains’ infrastructure to compromise multiple DeFi platforms simultaneously.

Users Report Aggressive Multi-Asset Drain Attempts

One affected user described encountering the malicious interface before official warnings circulated, detailing how the compromised site deployed a deceptive two-stage attack.

The hijacked frontend first requested what appeared to be a harmless signature containing only the number “1,” establishing initial wallet connection.

Immediately after this seemingly innocuous request, the interface triggered an unlimited number of approval prompts for NFTs, ETH, USDC, and WETH.

It asked for a simple signature, then instantly tried unlimited approvals to drain NFTs, ETH, and USDC,” the user reported. “If you weren’t paying attention, you could’ve lost everything.

The victim documented the attack through screenshots and video recordings, capturing the progression from initial signature request through multiple drain attempts.

Their investigation, conducted with AI assistance, examined browser configurations, extensions, DNS settings, and RPC endpoints before concluding that the attack pattern aligned with DNS hijacking methodology.

Another community member shared an experience with a separate, draining incident recently, describing themselves as a seasoned veteran and full-stack developer who still fell victim to sophisticated attacks.

Despite technical expertise, the user lost significant funds and spent 3 days developing a Jito bundle-based script to recover roughly 10-15% of the stolen assets through on-chain stealth operations.

October Records Lowest Crypto Hack Losses of the Year

The Aerodrome incident emerged during October’s unexpected security milestone, as the crypto market experienced its lowest monthly hack losses of the year.

Data from blockchain security firm PeckShield shows only $18.18 million was stolen across 15 separate incidents, representing a steep 85.7% decline from September’s $127.06 million.

Without the late-month Garden Finance exploit, total losses would have hovered near $7.18 million, the lowest single-month value since early 2023.

The largest incidents occurred at Garden Finance, Typus Finance, and Abracadabra, which collectively accounted for $16.2 million of total stolen funds.

Garden Finance, a Bitcoin peer-to-peer protocol, disclosed on October 30 that it had been exploited for more than $10 million after one of its solvers was compromised, with the breach affecting only the solver’s own inventory.

Typus Finance suffered an oracle manipulation attack on October 15 that drained roughly $3.4 million from its liquidity pools, traced to a flaw in one of its TLP contracts that caused the project’s native token to drop about 35%.

DeFi lending platform Abracadabra endured its third exploit since launch around the same time, resulting in roughly $1.8 million in MIM stablecoin losses after hackers bypassed solvency checks through a smart contract vulnerability.

Piyasa Fırsatı
TOP Network Logosu
TOP Network Fiyatı(TOP)
$0.000096
$0.000096$0.000096
0.00%
USD
TOP Network (TOP) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen [email protected] ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Crypto ETF Floodgates Open With SEC Listing Standards. What Does It Mean For Prices?

Crypto ETF Floodgates Open With SEC Listing Standards. What Does It Mean For Prices?

The post Crypto ETF Floodgates Open With SEC Listing Standards. What Does It Mean For Prices? appeared on BitcoinEthereumNews.com. The U.S. Securities and Exchange Commission (SEC) has cleared a path for a flood of new crypto exchange-traded products to hit the market, a move analysts say could reshape how money flows into digital assets. On Wednesday, the agency approved generic listing standards for “commodity-based trust shares” across regulated exchanges Nasdaq, Cboe BZX and NYSE Arca. Read more: SEC Makes Spot Crypto ETF Listing Process Easier, Approves Grayscale’s Large-Cap Crypto Fund The new rules remove the need for each crypto ETP to undergo its own individual rule filing under Section 19(b) of the Exchange Act. Instead, an offering whose underlying assets satisfy certain objective eligibility tests — for example, if the crypto trades on a market that is a member of the Intermarket Surveillance Group (ISG), or if the underlying asset’s futures contract is listed on a CFTC-regulated designated contract market for at least six months — can be listed using these generic standards. What’s next? The regulatory shift marks a watershed for the crypto industry, removing much of the procedural drag that has historically slowed getting new crypto products to the market, analysts said. “[The] crypto ETF floodgates are about to open,” said Nate Geraci, a well-followed ETF analyst and president of NovaDius Wealth Management. “Expect an absolute deluge of new filings and launches,” he said. “You may not like it, but crypto is going mainstream via the ETF wrapper.” Matt Hougan, chief investment officer of digital asset management firm and ETF issuer Bitwise, said the SEC’s move is a “coming of age” moment for crypto. “[It’s] a signal that we’ve reached the big leagues,” he wrote. “But it’s also just the beginning.” History backs up predictions that the number of new crypto ETF launches will accelerate under the new regime. When the SEC approved generic listing standards for…
Paylaş
BitcoinEthereumNews2025/09/20 14:14
OpenVPP accused of falsely advertising cooperation with the US government; SEC commissioner clarifies no involvement

OpenVPP accused of falsely advertising cooperation with the US government; SEC commissioner clarifies no involvement

PANews reported on September 17th that on-chain sleuth ZachXBT tweeted that OpenVPP ( $OVPP ) announced this week that it was collaborating with the US government to advance energy tokenization. SEC Commissioner Hester Peirce subsequently responded, stating that the company does not collaborate with or endorse any private crypto projects. The OpenVPP team subsequently hid the response. Several crypto influencers have participated in promoting the project, and the accounts involved have been questioned as typical influencer accounts.
Paylaş
PANews2025/09/17 23:58
US Senators Introduce SAFE Crypto Act to Target Rising Crypto Scams

US Senators Introduce SAFE Crypto Act to Target Rising Crypto Scams

The post US Senators Introduce SAFE Crypto Act to Target Rising Crypto Scams appeared first on Coinpedia Fintech News Crypto scams are getting faster, smarter and
Paylaş
CoinPedia2025/12/17 18:33