Need help? Support
BITCOIN
Tether Dominance USDT.D

Which DEXs faced DNS hijacking today?

Published 349 words 2 min read

TLDR

Aerodrome Finance (AERO) on Base confirmed a DNS hijacking of its web front end today, with users warned to avoid the primary domains while contracts remain secure, per an exchange notice and the teams posts on X (CoinDesk report, Aerodrome update).

  1. Compromised access points were the .finance and .box domains, redirecting users to phishing pages (CoinDesk).
  2. The team directed users to ethereum-name-service/">ENS-based mirrors and said contracts remain unaffected (Aerodrome X).
  3. Reports noted similar warnings from sister protocol Velodrome, indicating Box Domains-related risk, but no second DEX compromise confirmed yet (Yahoo Finance summary).

Deep Dive

1. Aerodrome Confirmed

Aerodrome Finance on Base reported a DNS hijack affecting its centralized domains, causing phishing redirects, while stating smart contracts were secure. This was reported by media and the teams official account (CoinDesk report, Aerodrome update).

  • The team asked users not to use the .finance and .box domains and to avoid signing transactions from unverified sites (CoinDesk).
  • They highlighted ENS-based mirrors as safer access points during remediation (Aerodrome X).
What this means

If you interacted with Aerodrome via its main domains today, consider revoking recent approvals and rechecking wallet activity before resuming use via verified links.

2. Possible Spillover Risk

Coverage notes Velodrome issued similar domain-security warnings tied to the same provider, suggesting a broader DNS risk vector, though a second confirmed hijack was not established in the sources reviewed (Yahoo Finance summary).

  • Media framed the event as likely connected to Box Domains infrastructure, with teams escalating to the provider (Yahoo Finance).
  • As of now, the clearly confirmed DNS hijacking incident is Aerodrome; treat other warnings as cautionary until an official confirmation emerges (CoinDesk).
What this means

Verify any DEX URL through official social posts before connecting wallets. Prefer decentralized naming mirrors when a team flags DNS issues and pause new approvals until recovery is confirmed.

Conclusion

Todays confirmed DNS hijack hit Aerodromes web front end, not its contracts, with phishing risk concentrated in the compromised domains. A related provider issue may affect others, but only Aerodrome is confirmed at this time. The practical step is to use verified links, prefer ENS mirrors during incidents, and review approvals before reconnecting.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top