TLDR
Aerodrome Finance (AERO), the leading decentralized exchange on Base, was the DEX hit by a DNS hijack that compromised its web front end and redirected users to phishing pages report.
- The team said contracts remained secure, but centralized domains were unsafe and advised using ethereum-name-service/">ENS mirrors until fixed update.
- Sister protocol Velodrome on Optimism reported a similar front-end issue during the same window coverage.
Deep Dive
1. What Happened
Reports say Aerodromes centralized domains were hijacked at the DNS level, sending visitors to fraudulent pages that attempted malicious wallet prompts. The team warned users to avoid the .finance and .box domains and temporarily use ENS-based mirrors, adding that on-chain smart contracts appeared unaffected by the incident report.
DNS hijacking targets the web layer that resolves domains, not the protocol itself. That means anyone who typed the correct URL could still end up on a spoofed site asking for harmful signatures or broad token approvals. This is why teams sometimes pivot to ENS mirrors, which are outside traditional DNS routing coverage.
Interactions failed at the website layer. If you interacted during the window, review recent approvals and verify access links via official channels before reconnecting.
2. Why It Matters
Front-end compromises can lead to wallet-draining via deceptive approvals even when contracts are safe, so user-level hygiene and link verification are critical. Media also noted that Velodrome, Aerodromes sister DEX on Optimism, flagged a similar front-end compromise in the same period, reinforcing the likelihood of a coordinated DNS issue at the domain level rather than a smart contract breach coverage.
Some coverage highlighted that Aerodrome previously faced a DNS-related issue in 2023, indicating that DNS remains a recurring weak point for popular DEX front ends. The operational takeaway is that front-end security and domain provider posture are part of a DEXs real risk surface, even when core contracts are audited and immutable analysis.
Treat domain integrity and official communication as part of your security checks. Bookmark verified links, favor protocol-driven or ENS-based access when advised, and avoid signing ambiguous prompts.
Conclusion
Aerodrome Finance on Base was targeted by a DNS hijack that redirected users through compromised domains, while core contracts were reported safe. The incident underscores that user risk can originate at the web layer, so verifying official access points and scrutinizing signature requests are essential during and after such events.
