TLDR
Aerodrome Finance (AERO) on Base confirmed a DNS hijacking of its web front end today, with users warned to avoid the primary domains while contracts remain secure, per an exchange notice and the teams posts on X (CoinDesk report, Aerodrome update).
- Compromised access points were the .finance and .box domains, redirecting users to phishing pages (CoinDesk).
- The team directed users to ethereum-name-service/">ENS-based mirrors and said contracts remain unaffected (Aerodrome X).
- Reports noted similar warnings from sister protocol Velodrome, indicating Box Domains-related risk, but no second DEX compromise confirmed yet (Yahoo Finance summary).
Deep Dive
1. Aerodrome Confirmed
Aerodrome Finance on Base reported a DNS hijack affecting its centralized domains, causing phishing redirects, while stating smart contracts were secure. This was reported by media and the teams official account (CoinDesk report, Aerodrome update).
- The team asked users not to use the .finance and .box domains and to avoid signing transactions from unverified sites (CoinDesk).
- They highlighted ENS-based mirrors as safer access points during remediation (Aerodrome X).
If you interacted with Aerodrome via its main domains today, consider revoking recent approvals and rechecking wallet activity before resuming use via verified links.
2. Possible Spillover Risk
Coverage notes Velodrome issued similar domain-security warnings tied to the same provider, suggesting a broader DNS risk vector, though a second confirmed hijack was not established in the sources reviewed (Yahoo Finance summary).
- Media framed the event as likely connected to Box Domains infrastructure, with teams escalating to the provider (Yahoo Finance).
- As of now, the clearly confirmed DNS hijacking incident is Aerodrome; treat other warnings as cautionary until an official confirmation emerges (CoinDesk).
Verify any DEX URL through official social posts before connecting wallets. Prefer decentralized naming mirrors when a team flags DNS issues and pause new approvals until recovery is confirmed.
Conclusion
Todays confirmed DNS hijack hit Aerodromes web front end, not its contracts, with phishing risk concentrated in the compromised domains. A related provider issue may affect others, but only Aerodrome is confirmed at this time. The practical step is to use verified links, prefer ENS mirrors during incidents, and review approvals before reconnecting.
