TLDR
Aerodrome Finance, a DEX on Base, suffered a DNS hijack via a front end attack today, affecting its primary web domain access and prompting user warnings to avoid the site for now (report).
- Attack vector: domain level DNS hijack that rerouted users to phishing pages, not a smart contract breach (coverage).
- Users were advised to avoid the main domain and use decentralized ethereum-name-service/">ENS mirrors until remediation is confirmed (report).
- Impact is still being assessed, with liquidity pools and treasuries reported intact at time of writing (update).
Deep Dive
1. What Happened
This was a front end incident at the domain level consistent with DNS hijacking, where traffic to the official site was intercepted and sent to lookalike phishing pages. That lets attackers push malicious signature prompts without touching on chain contracts. This pattern was explicitly noted as a DNS hijack against Aerodromes centralized domains (coverage).
Accessing the UI at the compromised domain, not the protocol contracts, was the risk. Signing prompts from a hijacked interface can authorize unintended actions.
2. Impact and Status
Early reports emphasized that protocol contracts remained unaffected and on chain liquidity and treasuries were intact while the team investigated and users were warned away from the main domain (report). Guidance also circulated to avoid centralized domains and use ENS based mirrors until remediation is verified (coverage).
If you only interacted via the spoofed website, exposure hinges on what you signed. Funds in the protocols pools were not the target.
3. Practical Safety
Domain hijacks exploit trust in familiar URLs, so the best immediate protections are verifying official access points and pausing signatures from the affected front end. Reports specifically advised using ENS mirrors rather than the compromised centralized domain until a formal clear signal is issued (coverage).
Treat any unexpected signature or approval prompt as high risk when a domain compromise is active. Wait for an official remediation notice before resuming normal use.
Conclusion
The DEX affected today was Aerodrome Finance, and the issue centered on a DNS front end hijack rather than a smart contract exploit. The practical takeaway is to avoid the compromised domain, use verified mirrors if provided, and resume normal interaction only after an official all clear is posted in the notices above.
