Need help? Support
BITCOIN
Tether Dominance USDT.D

Which DEXs reported DNS hijacks?

Published 455 words 3 min read

TLDR

Aerodrome and Velodrome reported DNS hijacks affecting their web front ends in the last few days.

  1. Aerodrome on Base warned of a DNS hijack and asked users to avoid its main domains. See the projects post and a report from a major outlet.
  2. Velodrome on ethereum/">Optimism issued similar guidance after its centralized domains were compromised, as covered alongside Aerodrome in a consolidated report.
  3. Both directed users to decentralized ENS mirrors while stating smart contracts were unaffected, per a security update and reporting.

Deep Dive

1. Aerodrome

Aerodrome said its centralized domains were hijacked, redirecting users to phishing pages. The team asked users to avoid .finance and .box domains while it investigated, noting contracts appeared secure in a direct post and in coverage by a leading crypto outlet.

  • The project posted status updates confirming a potential DNS hijack and that centralized domains remained compromised, with mirrors provided in the updates on the account above.
  • Independent reporting summarized the DNS hijack mechanism and the front end only nature of the compromise, advising mirror usage pending remediation.
What this means

If you interacted with Aerodromes website during the incident window, review recent approvals before further use and rely on the official mirrors cited in the post above.

2. Velodrome

Velodrome, Aerodromes sister DEX on Optimism, experienced an almost identical issue involving its centralized domains. Both DEXs were covered together as front-end compromises traced to DNS domain hijacking in a same-day report.

  • The consolidated update explained the redirection risk even when typing correct domains and noted both teams guidance to avoid main URLs while fixes progressed.
  • Prior incidents of similar nature were noted in the coverage above, highlighting a recurring DNS exposure for these front ends.
What this means

Treat lookalike URLs and unexpected signature prompts as high risk. Confirm you are using the exact links provided by the team in their latest post.

3. Mitigation and risk

Both teams emphasized that smart contracts remained secure, and they directed users to decentralized ENS mirrors while centralized domains were being remediated, as described in an outlets security brief and in the projects own post above.

  • The outlet report detailed that users should avoid the compromised domains and use ENS-hosted mirrors, which are less susceptible to traditional DNS hijacking.
  • Project updates reiterated the same, with mirrors listed and a commitment to further updates as the investigation progressed.
What this means

For web access to DEXs, prefer official ENS mirrors when teams provide them, and double check any transaction prompts before signing.

Conclusion

Two major DEXs, Aerodrome and Velodrome, reported DNS hijacks that compromised their web front ends but not their smart contracts. The immediate safeguard was to avoid main domains and use ENS mirrors per the notices above, underscoring how domain-layer attacks can affect users even when on-chain code remains intact.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top