TLDR
Aerodrome Finance (AERO) on Base reported a frontend attack via DNS hijacking that compromised its web domains, while smart contracts remained unaffected, per a media report and project updates here.
- Attack vector: DNS hijack of the DEX website routing users to phishing pages; contracts were not breached report.
- Status: Users were told to avoid aerodrome.finance and .box and use ethereum-name-service/">ENS-based mirrors; losses were unconfirmed report.
- Related: Sister DEX Velodrome also reported a similar frontend compromise the same day coverage.
Deep Dive
1. Who Was Hit
Aerodrome Finance (AERO), a leading DEX on Base, disclosed a frontend compromise on 22 Nov, warning users off its primary domains as a precaution while investigating the incident coverage.
The early reports emphasize that protocol smart contracts and treasuries were not compromised, which limits direct on-chain loss risk relative to a code exploit report.
The risk centered on phishing via the site interface, not on-chain logic. Exposure would have come from signing malicious prompts.
2. Attack Vector
Reports point to DNS hijacking of centralized domains, redirecting users to lookalike sites that pushed malicious signature requests and unlimited approval prompts, a common phishing pattern in web-layer compromises report.
ENS-hosted mirrors were recommended because they are less susceptible to traditional DNS tampering, aligning with best practice to harden access points when web2 infrastructure is targeted coverage.
The safest near-term approach is to verify official access URLs and be skeptical of new signature requests until an all-clear is posted.
3. Scope And Implications
Same-day coverage indicated Velodrome, the Optimism-based sister DEX, experienced a similar frontend compromise, suggesting the vector may have involved shared domain infrastructure providers coverage.
Because contracts were reported safe, systemic liquidity or LP pool risk was limited in the immediate term, though user-level phishing losses can still occur if malicious prompts were signed report.
Monitor official updates before interacting and scrutinize any recent approvals on affected wallets.
Conclusion
Aerodrome Finance faced a frontend DNS hijack that targeted its web entry points, not its on-chain contracts, and advised users to avoid compromised domains and use ENS mirrors. A similar incident was reported by Velodrome, pointing to a likely shared web-layer issue. The key takeaway is to verify access URLs and be cautious with signatures until an official resolution is confirmed.
