TLDR
Aerodrome Finance (AERO) on Base is the DEX that suffered a DNS hijack, causing a front?end compromise and phishing redirects, per an official update and media reports.
- Aerodromes centralized domains were hijacked and redirected to phishing sites, confirmed in a front?end attack notice.
- The team warned users to avoid .finance and .box domains and posted guidance on X, noting centralized domains remain compromised.
- Smart contracts remained secure; the issue was limited to the web interface, reiterated in the media coverage.
Deep Dive
1. Affected DEX
Aerodrome Finance (AERO), Bases leading DEX, reported that its centralized domains were hijacked and served malicious content to users. Coverage emphasized a DNS hijack pattern that redirected visitors to spoofed sites attempting to solicit harmful wallet signatures in a front?end attack report.
If you visited Aerodrome via its usual web domains around the incident, your risk is phishing on the interface, not contract?level loss.
2. User Safety Steps
Aerodromes X account stated the .finance and .box domains were compromised and asked users not to use them while investigations continue. The team highlighted decentralized ethereum-name-service/">ENS mirrors as safe alternatives until the main domains are cleared in an official update.
- Avoid aerodrome.finance and aerodrome.box during the investigation (per the notice above).
- Use the ENS mirrors the team referenced until an all?clear is posted.
- If you interacted with the spoofed site, revoke recent approvals and check for suspicious signatures.
Verify the domain before signing anything. Prefer ENS-hosted mirrors as a temporary safety path.
3. Scope of Impact
Reports and team posts consistently note that the incident did not compromise Aerodromes smart contracts; the attack targeted the DNS/front?end layer. Sister protocol Velodrome on Optimism reported a similar issue, suggesting the problem centered on centralized domain infrastructure, as covered in a follow?up report.
- On?chain liquidity pools and treasuries remained intact.
- The phishing risk arose from malicious signature prompts on spoofed interfaces.
- Front?end fixes and domain provider coordination are in progress per public updates.
On?chain funds were not directly at risk. The main hazard was users signing malicious approvals on redirected web pages.
Conclusion
Aerodrome Finance on Base faced a DNS hijack that redirected its web domains to phishing pages. Until the team confirms safety, avoid the compromised domains, use the ENS mirrors, and revoke any recent approvals if you visited the spoofed interface.
