Need help? Support
BITCOIN
Tether Dominance USDT.D

Which DEX was hijacked on Base?

Published 357 words 2 min read

TLDR

Aerodrome Finance was the DEX hijacked on Base via a front?end (DNS) compromise, not its smart contracts, per a confirmed media report. See the front?end attack coverage.

  1. Attack vector was DNS hijack that redirected users to phishing pages, as reported in the article above.
  2. Teams urged avoiding .finance and .box domains and using decentralized mirror links, per a media update.
  3. Sister DEX Velodrome on ethereum/">Optimism faced a similar front?end compromise, per a news report.

Deep Dive

1. The DEX

The hijacked Base DEX was Aerodrome Finance (often referred to as AERO). Multiple outlets identified Aerodrome as Bases leading DEX impacted by a front?end compromise rather than a contract breach, with teams posting warnings to avoid central domains and use ENS mirrors instead, as noted in the coverage above.

What this means

The protocols smart contracts were reportedly safe; the risk was the web interface pushing malicious prompts.

2. Attack Vector

Reports point to a DNS hijacking of centralized domains that redirected visitors to look?alike phishing sites, prompting malicious signatures and unlimited approvals across assets such as ETH and USDC, per the CryptoNews report.

  1. DNS hijack enables attackers to redirect even when the correct URL is entered, explained in the report above.
  2. Teams recommended decentralized ENS mirrors to bypass DNS risks, per the same update.
What this means

Front?end compromises can trick users into signing bad transactions even if protocol code is fine.

3. Scope and Impact

The incident coincided with a similar front?end issue at Velodrome (Optimism), suggesting a coordinated DNS domain problem across sister platforms, per The Blocks report.

  1. Aerodromes team posted real?time warnings and indicated smart contracts remained secure, per the CoinDesk article.
  2. Media reported prior similar attacks in late 2023, underscoring recurring DNS risks for front?ends, per The Block coverage above.

Risk note: Front?end phishing plus low?friction signatures can drain wallets quickly when users accept unlimited approvals.

Conclusion

Aerodrome Finance on Base suffered a DNS hijack that compromised its web front?end, while smart contracts were reported unaffected. The key takeaway is to treat domain?level incidents as distinct from protocol code risk and heed official mirror links when front?ends are compromised.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top