Ethereum News Update: Major DEX Compromised as Centralized DNS Vulnerability Threatens DeFi Security
- Aerodrome and Velodrome DEXs suffered DNS hijacking attacks, redirecting users to phishing sites via centralized domain vulnerabilities. - Attackers exploited compromised domains to trick users into signing malicious transactions, mirroring a 2023 incident that caused $300,000+ losses. - Platforms urged users to revoke token approvals and use ENS mirrors, emphasizing secure smart contracts but highlighting DeFi's front-end risks. - The breach occurred days after Aerodrome's planned merger with Velodrome,
Aerodrome Finance, recognized as the top decentralized exchange (DEX) on
This incident is reminiscent of a similar attack in late 2023, when the front-ends of Aerodrome and Velodrome were also compromised,
The DNS hijack took advantage of weaknesses in centralized domain registrars, sending users to fake sites that closely resembled the DEXs' original interfaces.
This event underscores persistent threats in decentralized finance (DeFi), where vulnerabilities in front-end infrastructure—unlike on-chain smart contract exploits—can be targeted without breaching the protocol itself.
Aerodrome’s team is currently working with its domain provider, My.box, to investigate the incident and
The coordinated nature of this attack raises alarms about broader weaknesses in domain management, suggesting that other DeFi platforms could face similar risks. As the sector continues to move toward decentralization, dependence on centralized DNS remains a major concern.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
A whale sold 700.2 WBTC in the past two days, worth nearly $60 million.
Forward Industries transferred 1.727 million SOL tokens, worth $219.32 million, to a wallet address.
Federal Reserve's Collins: There are still reasons to be cautious about a December rate cut.