Need help? Support
BITCOIN
Tether Dominance USDT.D

Which DEX faced DNS hijacking?

Published 341 words 2 min read

TLDR

Aerodrome Finance (AERO) on Base and Velodrome (VELO) on ethereum/">Optimism faced DNS hijacking that compromised their front ends, per a CoinDesk report and a The Block article.

  1. Teams warned users to avoid .finance and .box domains and use ENS mirrors, as seen in Aerodromes post on X.
  2. Smart contracts remained secure; the compromise was the web front end, per the CoinDesk report.
  3. A domain provider issue was suspected during mitigation, per the The Block article.

Deep Dive

1. Affected DEXs

Aerodrome Finance (AERO) and Velodrome (VELO) reported their centralized domains were hijacked and redirected to malicious sites that mimicked their UIs to solicit harmful signatures. Coverage specifies Aerodrome on Base and Velodrome on Optimism, with both urging alternative access via ENS mirrors, per the CoinDesk report and the The Block article.

What this means

If you visited those domains during the incident window, the risk was phishing via wallet signature prompts rather than on-chain contract theft.

2. Front End vs Smart Contracts

Reports and team posts emphasized that protocol smart contracts and treasuries were not compromised; the issue was DNS-level redirection of web traffic to spoofed pages. This distinction matters because liquidity pools and core logic remained safe even as the UI became a phishing vector, per the CoinDesk report.

What this means

Operational risk was off-chain (browser and domain). The practical threat was approving malicious transactions, not contract-level exploits.

3. User Guidance

Aerodromes real-time updates advised avoiding the compromised .finance and .box domains and using decentralized ENS mirror links during remediation, as seen in Aerodromes post on X. The Block also noted outreach to the domain provider and prior similar incidents, indicating a recurring DNS attack pattern, per the The Block article.

What this means

Verify URL pathways and consider limiting approvals when accessing DEX UIs during incident windows to reduce exposure to phishing.

Conclusion

Aerodrome (AERO) and Velodrome (VELO) experienced DNS hijacking that redirected users to phishing front ends, while core smart contracts stayed secure. The primary risk was malicious signature requests via spoofed sites, and the teams advised using ENS mirror links and avoiding compromised domains until remediation.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top