TLDR
Aerodrome Finance and Velodrome reported a frontend hijack caused by a DNS compromise, prompting users to avoid their main domains while investigations proceed news report.
- Aerodrome warned of a frontend compromise and said smart contracts appear secure official post.
- Coverage confirmed Aerodromes centralized domains were compromised and suggested ethereum-name-service/">ENS mirrors as safer access media update.
- Additional reporting highlighted both Aerodrome on Base and Velodrome on Optimism were affected coverage.
Deep Dive
1. Aerodrome Details
Aerodrome Finance (Base) said it is investigating a frontend compromise and asked users not to access any URLs until safety is confirmed, noting smart contracts appear secure official post.
- Media described a DNS hijack redirecting users to phishing sites and advised use of ENS mirrors while the team works on remediation media update.
- Reports detailed malicious signature prompts and domain-level compromise, not contract-level exploits coverage.
Frontend attacks target the website layer. Smart contracts can remain intact, but users face phishing and malicious approvals if they visit compromised domains.
2. Velodrome Mention
Velodrome (Optimism) was reported alongside Aerodrome as experiencing a front-end compromise via DNS issues, with teams urging users to avoid main domains (see the report above from The Block).
- The report above notes both DEXs pushed warnings, emphasizing the problem was domain-level and advising alternative access paths.
If you used Velodromes main domains during the incident window, review recent approvals and verify you interacted with authentic interfaces.
3. Why It Matters
Front-end hijacks can trick users into signing harmful transactions despite secure contracts. Reports flagged malicious signature requests and unlimited approvals on compromised interfaces coverage.
- ENS mirrors were cited as safer, decentralized access while centralized domain issues are fixed media update.
- The incident underscores the need to verify domain authenticity and scrutinize approvals during suspicious periods official post.
Treat UI prompts with caution, especially during active incident notices; confirm domains and approval scopes before signing any transaction.
Conclusion
Aerodrome Finance and Velodrome reported a DNS-driven frontend hijack, with warnings to avoid primary domains while smart contracts remained secure. The practical takeaway is to verify access paths and approvals during incidents to reduce phishing exposure.
