TLDR
Aerodrome Finance, a leading decentralized exchange on Base, was hit by a front end DNS hijacking that redirected users to phishing pages per a CoinDesk report.
- The hijack targeted aerodrome.finance and aerodrome.box, steering users to fake signing prompts, according to the CoinDesk report.
- The team said smart contracts were unaffected and directed users to ethereum-name-service/">ENS mirrors, per a CryptoNews piece.
Deep Dive
1. Front End Breach
This was a DNS hijacking of centralized domains that rerouted users to a malicious interface rather than a smart contract exploit. The compromised pages attempted to lure users into signing deceptive transactions and unlimited approvals, as covered in a Yahoo Finance write?up. The incident aligns with typical front end compromises where domain control is seized and traffic is funneled to phishing pages, as first noted in the CoinDesk report above.
Even when protocol contracts are safe, a hijacked website can trick users into harmful wallet signatures. The risk is at the interface, not the code.
2. Contracts Safe, Temporary Workarounds
Aerodrome stated that core smart contracts were unaffected and urged users to avoid the .finance and .box domains, pointing instead to ENS-backed mirrors that are insulated from DNS tampering, consistent with the CryptoNews piece and a Binance Square update. The guidance also included revoking recent token approvals if users interacted with the compromised front end, a standard precaution after phishing attempts.
Access the DEX only via verified links and consider revoking recent approvals if you visited the affected domains. Interface compromises can persist even when on-chain contracts remain sound.
Conclusion
The Base DEX that faced hijacking was Aerodrome Finance. The attack targeted its web front end via DNS, not its smart contracts, which limits protocol risk but raises user phishing risk. Practical caution is to use verified access points and avoid interacting with compromised domains until the project confirms restoration.
