TLDR
Aerodrome Finance on Base and Velodrome on ethereum/">Optimism reported DNS hijacks that compromised their web front ends, while smart contracts remained secure per an industry report.
- Aerodrome Finance (Base): front-end DNS hijack, use ENS mirrors per the projects updates.
- Velodrome (Optimism): impacted in the same incident per the projects summary.
Deep Dive
1. Aerodrome (Base)
Aerodromes centralized domains were hijacked and redirected users to phishing content, prompting a switch to ENS-hosted mirrors. The incident was covered by multiple outlets and confirmed by Aerodromes X posts, noting contracts were unaffected and advising users to avoid the .finance and .box domains until remediation is complete. See the industry report and the projects update.
- Aerodrome warned of a front-end compromise and asked users to avoid its main domains while using ENS mirrors (project update).
- Coverage repeated that smart contracts were secure; the compromise targeted web routing and signatures (news summary).
If you accessed Aerodrome via its hijacked domains, review recent approvals and revoke any suspicious permissions. Use verified ENS mirrors until the team confirms restoration.
2. Velodrome (Optimism)
Velodrome was reported as part of the same DNS hijack wave affecting centralized domains, with the team coordinating updates alongside Aerodrome. The event was cited in media and in Aerodromes follow-up stating both exchanges had domains hijacked. See the industry report and the project summary noting both were hit.
- The incident mirrors Aerodromes pattern: phishing via front-end redirection, contracts intact, avoid centralized domains during remediation (industry report).
Treat any recent Velodrome interactions through affected domains with caution. Confirm URLs, monitor permissions, and wait for the teams confirmation before reconnecting.
Conclusion
Two leading L2 DEXs, Aerodrome (Base) and Velodrome (Optimism), saw DNS hijacks affecting their front ends. The core takeaway is operational: avoid centralized domains, prefer verified ENS mirrors, and revoke risky approvals until each team confirms a full fix.
