{"id":20355,"date":"2025-05-12T23:42:17","date_gmt":"2025-05-12T23:42:17","guid":{"rendered":"https:\/\/gold.creditcard\/curve-finance-warns-its-dns-has-been-hijacked-again\/"},"modified":"2025-05-12T23:42:17","modified_gmt":"2025-05-12T23:42:17","slug":"curve-finance-warns-its-dns-has-been-hijacked-again","status":"publish","type":"post","link":"https:\/\/gold.creditcard\/es\/curve-finance-warns-its-dns-has-been-hijacked-again\/","title":{"rendered":"Curve Finance warns its DNS has been hijacked again"},"content":{"rendered":"<p>Decentralized finance (DeFi) protocol Curve Finance has warned that a hacker has again hijacked its domain name system (DNS), sending users to a malicious website.\u00a0\u00a0<\/p>\n<p>In the second attack on its infrastructure in a week, the \u201ccurve.fi DNS might be hijacked. Don\u2019t interact!\u201d the team <a href=\"https:\/\/x.com\/CurveFinance\/status\/1922040492121829678\" target=\"null\" title=\"null\">said<\/a> in a May 12 warning to X.<\/p>\n<p>In a follow-up post to a user asking whether it was <a href=\"https:\/\/cointelegraph.com\/learn\/articles\/8-most-common-cyberattacks-and-how-to-prevent-them\" target=\"null\" title=\"null\">a hack or a hijack<\/a>, the Curve Team <a href=\"https:\/\/x.com\/CurveFinance\/status\/1922046387971141743\" target=\"null\" title=\"null\">said<\/a> the website \u201cPoints to the wrong IP\u201d when users try to visit. A DNS works like a directory that translates domain names into IP addresses.\u00a0<\/p>\n<p><em>Source: <\/em><a href=\"https:\/\/x.com\/CurveFinance\/status\/1922046387971141743\" target=\"null\" title=\"null\"><em>Curve Finance<\/em><\/a><\/p>\n<p>The team also <a href=\"https:\/\/x.com\/CurveFinance\/status\/1922057828186853829\" target=\"null\" title=\"null\">said<\/a> in another update that the \u201cPassword is secure,\u201d its two-factor authentication was set up a \u201clong time ago,\u201d and a question has been sent to the \u201cregistrar now.\u201d<\/p>\n<p>\u201dWhile all smart contracts are safe, the domain name points to a malicious site which can drain your wallet! We are investigating and working on recovering the access. No sign of a compromise on our side,\u201d Curve <a href=\"https:\/\/x.com\/CurveFinance\/status\/1922069785795342654\" target=\"_blank\" title=\"https:\/\/x.com\/CurveFinance\/status\/1922069785795342654\">said<\/a>. <\/p>\n<p>Curve Finance was hit with a similar <a href=\"https:\/\/cointelegraph.com\/news\/breaking-curve-finance-team-warns-users-to-avoid-using-site-until-further-notice\" target=\"null\" title=\"null\">front end attack in August 2022<\/a>. In a post-mortem,\u00a0 the consensus was that<a href=\"https:\/\/cointelegraph.com\/news\/curve-finance-exploit-experts-dissect-what-went-wrong\" target=\"null\" title=\"null\"> the attackers managed to clone the Curve Finance website<\/a> and reroute the DNS server to the fake page.<\/p>\n<p>Users who attempted to use the platform had their funds drained into a pool operated by the attackers.<\/p>\n<p>Cointelegraph has contacted Curve Finance for comment. <\/p>\n<h2>Curve Finance potential front-end attack<\/h2>\n<p>Onchain security firm Blockaid also detected unusual activity from the Curve website recently, warning users to stay away and avoid interacting for now.<\/p>\n<p>It could be a case of a \u201cpotential frontend attack,\u201d <a href=\"https:\/\/x.com\/blockaid_\/status\/1922050920315052433\" target=\"null\" title=\"null\">according<\/a> to the security firm, which is when hackers <a href=\"https:\/\/pwp.stevecassidy.net\/security\/frontend\/#:~:text=These%20are%20attacks%20where%20the,needed%20to%20mitigate%20these%20attacks.\" target=\"null\" title=\"null\">target<\/a> the part of the website users interact with, such as the buttons, forms, or text on the site, to steal sensitive data.<\/p>\n<p><em>Source: <\/em><a href=\"https:\/\/x.com\/blockaid_\/status\/1922050920315052433\" target=\"null\" title=\"null\"><em>Blockaid<\/em><\/a><\/p>\n<p>\u201cIf you\u2019re connected, please refrain from signing transactions and avoid interactions with the DApp until the issue is resolved. We\u2019re working closely with affected partners. More updates soon,\u201d Blockaid said.<\/p>\n<p><em><strong>Related: <\/strong><\/em><a href=\"https:\/\/cointelegraph.com\/news\/crypto-hackers-steal-92-m-april-hacked-funds-1-7-b-2025\" target=\"null\" title=\"null\"><em><strong>Crypto hackers hit DeFi for $92M in April as attacks double from March<\/strong><\/em><\/a><\/p>\n<h2>Second attack in a week<\/h2>\n<p>This is the second time Curve Finance has been targeted in the last week. On May 5, <a href=\"https:\/\/cointelegraph.com\/news\/tron-dao-curve-finance-latest-victims-x-hacks\" target=\"null\" title=\"null\">a hacker took over its <\/a><a href=\"https:\/\/cointelegraph.com\/news\/tron-dao-curve-finance-latest-victims-x-hacks\" target=\"_blank\" title=\"https:\/\/cointelegraph.com\/news\/tron-dao-curve-finance-latest-victims-x-hacks\">official X<\/a> handle. <\/p>\n<p>\u201cTo clarify: the incident was limited strictly to the X account. No other Curve accounts were affected. No security issues were found on our side, no user funds were impacted, and there were no victims of phishing links that the hacker posted,\u201d the team said in a follow-up May 6 post.\u00a0<\/p>\n<p><em>Source: <\/em><a href=\"https:\/\/x.com\/CurveFinance\/status\/1919692884011331711\" target=\"null\" title=\"null\"><em>Curve Finance<\/em><\/a><\/p>\n<p>Access to the Curve Finance X account was restored quickly, and the cause is still under investigation.<\/p>\n<p>A slew of other high-profile X accounts have also been <a href=\"https:\/\/cointelegraph.com\/news\/hackers-accessed-new-york-post-x-account-scam-crypto-twitter\" target=\"null\" title=\"null\">taken over by bad actors this year<\/a>. On May 2, the Tron DAO account was hijacked; meanwhile, on April 15, a member of the UK\u2019s Parliament, Lucy Powell, had<a href=\"https:\/\/cointelegraph.com\/news\/british-mp-x-account-hacked-promotes-scam-house-of-commons-coin\" target=\"null\" title=\"null\"> her account taken over to promote a scam crypto token<\/a> called the House of Commons Coin (HOC).<\/p>\n<p><em><strong>Magazine: <\/strong><\/em><a href=\"https:\/\/cointelegraph.com\/magazine\/financial-nihilism-crypto-over-dream-big-again\/\" target=\"null\" title=\"null\"><em><strong>Financial nihilism in crypto is over \u2014 It\u2019s time to dream big again<\/strong><\/em><\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>Decentralized finance (DeFi) protocol Curve Finance has warned that a hacker has again hijacked its domain name system (DNS), sending users to a malicious website.\u00a0\u00a0 In the second attack on its infrastructure in a week, the \u201ccurve.fi DNS might be hijacked. Don\u2019t interact!\u201d the team said in a May 12 warning to X. In a [&hellip;]<\/p>","protected":false},"author":0,"featured_media":20356,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_eb_attr":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[9],"tags":[],"class_list":["post-20355","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-finance"],"_links":{"self":[{"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/posts\/20355","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/comments?post=20355"}],"version-history":[{"count":0,"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/posts\/20355\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/media\/20356"}],"wp:attachment":[{"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/media?parent=20355"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/categories?post=20355"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/tags?post=20355"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}