TLDR
Aerodrome Finance and Velodrome reported a DNS hijack of their centralized domains, causing front?end compromises that redirected users to phishing sites, while smart contracts remained secure per their updates and media reports (The Block report).
- Aerodrome told users to avoid its .finance and .box domains and use decentralized ethereum-name-service/">ENS mirrors; contracts appear secure (Aerodrome update).
- Velodrome faced a similar compromise during the same incident, per media coverage (The Block report).
- Investigations are ongoing, with signs of mitigation later the same day (CoinDesk coverage).
Deep Dive
1. What Happened
Both DEX front?ends were hijacked via DNS manipulation, redirecting correct URLs to malicious lookalike sites. Aerodrome and Velodrome urged users to avoid primary domains and switch to decentralized ENS mirrors, noting that smart contracts were unaffected (CoinDesk coverage, The Block report).
On?chain funds and logic stayed intact, but the web gateways users rely on were unsafe. If you visited the spoofed sites, approvals and signatures are the main risk vector.
2. Why It Matters
DNS hijacks target centralized web infrastructure, not the underlying DeFi smart contracts. Reports described malicious signature prompts designed to drain assets if users approved them (Yahoo Finance summary, CryptoNews article). This underscores a recurring DeFi weakness: secure protocols can still be exposed via compromised front?ends.
3. Mitigation and Status
Aerodromes official posts flagged the ongoing compromise, advised avoiding centralized domains, and highlighted decentralized ENS mirrors as safer access points while investigations continued (Aerodrome update, Aerodrome initial alert). Media coverage indicated the fraudulent sites stopped loading later the same day, suggesting remediation progress (The Block report).
Risk note: Phishing via front?end compromises can lead to unlimited token approvals and asset drains. Cause ? effect is web gateway takeover leading to wallet?level authorization traps.
Conclusion
Aerodrome and Velodrome experienced DNS hijacks that compromised their front?end domains, but on?chain contracts remained secure. The practical risk was malicious approvals, not protocol insolvency. Monitor official updates and use decentralized mirrors when advised until domain integrity is confirmed.
Confidence: high because multiple reputable reports and the projects official posts align on the incident and scope.
