• Home
  • Live Rates
  • Privacy Policy
  • Shop
  • Terms of Service
Saturday, May 24, 2025
  • Home
  • Crypto News
  • Bitcoin
  • Ethereum
  • NFT
  • DeFi
  • Blockchain
  • Metaverse
  • Altcoin
  • Tether
  • Solana
    • Dogecoin
  • Live Rates
  • Shop
No Result
View All Result
XXL24
Ledger - Crypto Beginners Pack
  • Home
  • Crypto News
  • Bitcoin
  • Ethereum
  • NFT
  • DeFi
  • Blockchain
  • Metaverse
  • Altcoin
  • Tether
  • Solana
    • Dogecoin
  • Live Rates
  • Shop
No Result
View All Result
XXL24
No Result
View All Result

Over 120 DeFi protocols at risk in suspected Squarespace DNS attack

July 11, 2024
in DeFi
0

Key Takeaways

  • Blockaid identified a DNS attack targeting DeFi apps hosted on Squarespace.
  • MetaMask is actively warning users about compromised DeFi applications.

Share this article

Blockchain security firm Blockaid has warned of a possibly widespread domain hijacking incident affecting Compound, Celer Network, and potentially 120 other protocols. According to the report, a new frontend attack was detected today, July 11, preceded by an initially benign attack from July 6.

This development follows a Crypto Briefing report earlier today about Compound Labs’ confirmation that the front-end for their website, compound[.]finance was compromised. Blockaid notes that the attacker has also attempted to compromise Celer Network after gaining control of Compound’s DNS.

The attack was first detected when users noticed Compound’s interface at compound[.]finance redirecting to a malicious website containing a token-draining application. Celer Network also confirmed an attempted takeover of its domain, which was thwarted by its monitoring system.

Blockaid’s investigation suggests the attacker is specifically targeting domain names provided by Squarespace, potentially putting any DeFi app using a Squarespace domain at risk.

“From initial assessment, it appears that the attackers are operating by hijacking DNS records of projects hosted on SquareSpace,” the security firm stated on X.

0xngmi, developer of blockchain analytics platform DefiLlama, shared a list of 125 DeFi protocols that may be affected by this attack. The list includes prominent projects such as Thorchain, Aptos Labs, Near, Flare, Pendle Finance, dYdX, Polymarket, Satoshi Protocol, Nirvana, Ferrum, and MantaDAO, among others.

In response to the threat, Web3 wallet MetaMask announced it is working to warn users of potentially compromised apps associated with the attack. “For those of you using MetaMask, you’ll see a warning provided by @blockaid_ if you attempt to transact on any known site that’s involved in this current attack,” the company stated.

This domain-name hijacking incident is the latest in a series of attacks targeting the DeFi sector. In December, a similar attack saw malicious code injected into the Ledger Connect library, affecting a large portion of the Ethereum Virtual Machine ecosystem.

Possible exploit methods

The possible DNS attack on over 120 DeFi protocols has sparked speculation about the potential exploit methods employed.

According to a security researcher in direct contact with this author, the possible methods could range from sophisticated pre-registration tactics, in which threat actors may have registered domains before the transfers from Google to Squarespace were completed, to mass domain sign-ups potentially mixed with legitimate Squarespace domains.

Sapphire

The researcher, who responded to queries on the condition of anonymity, noted that this series of incidents could have also been executed through DNS cache poisoning, more commonly known as DNS spoofing, a method in which false data is injected into a DNS cache, resulting to DNS queries returning an incorrect response, directing users to wrong, possibly malicious websites.

Based on this author’s conversations with the security researcher, more alarming theories suggest a direct breach of Squarespace’s security, potentially allowing attackers to manipulate DNS records directly from the source.

While a typical domain transfer lock-in period makes some attack vectors less likely, the wide-ranging impact suggests a systemic vulnerability. For context, Squarespace announced that it had completed the acquisition of Google’s domain business on September 7, 2023.

It’s crucial to note that these are speculative theories, not confirmed facts about the attack method. The exploit likely leveraged a combination of tactics or an as-yet-undisclosed vulnerability in the domain management system.

This story is developing and will be updated. Crypto Briefing has reached out to Squarespace for comments.

Share this article

Follow Crypto Briefing on Google News

This news is republished from another source.


Previous Post

Tether Issues Update On USDT Halt on Algorand, EOS, & Others

Next Post

MOONHOP’s Presale, Ethereum NFT Dip & BRETT Optimism

Next Post

MOONHOP’s Presale, Ethereum NFT Dip & BRETT Optimism

Name Price
Kinza Babylon Staked BTC
Kinza Babylon Staked BTC (KBTC)
$83,270.00
Steakhouse EURCV Morpho Vault
Steakhouse EURCV Morpho Vault (STEAKEURCV)
$0.000000
Vested XOR
Vested XOR (VXOR)
$3,404.23
ICPanda DAO
ICPanda DAO (PANDA)
$0.003106
TruFin Staked APT
TruFin Staked APT (TRUAPT)
$8.02
bitcoin
Bitcoin (BTC)
$108,991.00
ethereum
Ethereum (ETH)
$2,558.88
tether
Tether (USDT)
$1.00
ripple
XRP (XRP)
$2.35
binancecoin
BNB (BNB)
$674.85

Dogecoin

Will Dogecoin Recover or Dive Below $0.1? 5thScape Set to Dominate 2024! %

July 15, 2024

Investors Shift to Clandeno (CLD) ICO Amid Global Market Uncertainty as Dogecoin (DOGE) and Polkadot (DOT) Drop

July 14, 2024

Dogecoin (DOGE) and Solana (SOL) Lead Crypto Market Recovery as Bitcoin (BTC) Reclaims $60K

July 14, 2024

DOGECOIN PRICE ANALYSIS & PREDICTION (July 13) – Doge Trades Calmly At $0.1, Can It Gain Strength From This Key Level? 

July 14, 2024

Analyst Who Bought Solana At $0.11 And Sold For $250 Says Buy ETFSwap (ETFS) At $0.01831 Now Instead Of Dogecoin (DOGE)

July 13, 2024

Leap Ahead with MOONHOP Presale As 4900% Growth Projection Dwarfs Notcoin & Dogecoin’s Declines

July 13, 2024

Metaverse

Ciz Verse Announces the Launch of Its Bitcoin-Powered Metaverse

July 15, 2024

Mil.k partners AirAsia rewards and The Sandbox to engage consumers in the metaverse

July 15, 2024

Lado Okhotnikov Reveals The Secrets Of The Realistic Meta Force Metaverse

July 14, 2024

GensoKishi Metaverse (MV) Price Down 18.4% This Week

July 14, 2024

The 3 Smartest Metaverse Stocks to Buy With $500 Right Now

July 14, 2024

Top 3 Metaverse Tokens For 3X Surge This Bull Rally!

July 13, 2024

transcosmos launches Roblox metaverse services with EbuAction

July 13, 2024
No Result
View All Result

Pages

  • Home
  • Live Rates
  • Privacy Policy
  • Shop
  • Terms of Service

Tether

Zimbabwe ZiG Hits Record Low as Interest in Tether (USDT) Rises

July 15, 2024

Solana

How Solana flipped Ethereum, Bitcoin in NFT Adoption

July 15, 2024

Solana Reaches Market Capitalization of $67.27 Billion (SOL)

July 14, 2024

Advertisement

  • Shop
  • Privacy Policy
  • Terms of Service

© 2023 XXL24


No Result
View All Result
  • Home
  • Crypto News
  • Bitcoin
  • Ethereum
  • NFT
  • DeFi
  • Blockchain
  • Metaverse
  • Altcoin
  • Tether
  • Solana
    • Dogecoin
  • Live Rates
  • Shop

© 2023 XXL24


  • Kinza Babylon Staked BTCKinza Babylon Staked BTC(KBTC)$83,270.000.00%
  • Steakhouse EURCV Morpho VaultSteakhouse EURCV Morpho Vault(STEAKEURCV)$0.000000-100.00%
  • Vested XORVested XOR(VXOR)$3,404.231,000.00%
  • ICPanda DAOICPanda DAO(PANDA)$0.003106-39.39%
  • TruFin Staked APTTruFin Staked APT(TRUAPT)$8.020.00%
  • bitcoinBitcoin(BTC)$108,991.00-0.56%
  • ethereumEthereum(ETH)$2,558.88-0.90%
  • tetherTether(USDT)$1.000.01%
  • rippleXRP(XRP)$2.35-0.87%
  • binancecoinBNB(BNB)$674.850.65%
  • solanaSolana(SOL)$176.93-2.49%
  • Wrapped SOLWrapped SOL(SOL)$143.66-2.32%
  • usd-coinUSDC(USDC)$1.000.00%
  • dogecoinDogecoin(DOGE)$0.228052-3.24%
  • cardanoCardano(ADA)$0.76-3.05%
  • tronTRON(TRX)$0.2700280.14%
  • staked-etherLido Staked Ether(STETH)$2,556.14-0.74%
  • wrapped-bitcoinWrapped Bitcoin(WBTC)$108,797.00-0.41%
  • Gaj FinanceGaj Finance(GAJ)$0.0059271.46%
  • Content BitcoinContent Bitcoin(CTB)$24.482.55%
  • SuiSui(SUI)$3.64-1.26%
  • USD OneUSD One(USD1)$1.000.11%
  • HyperliquidHyperliquid(HYPE)$35.310.89%
  • Wrapped stETHWrapped stETH(WSTETH)$3,076.49-0.95%
  • chainlinkChainlink(LINK)$15.62-4.24%
  • UGOLD Inc.UGOLD Inc.(UGOLD)$3,042.460.08%
  • avalanche-2Avalanche(AVAX)$23.11-5.78%
  • ParkcoinParkcoin(KPK)$1.101.76%
  • stellarStellar(XLM)$0.288415-2.09%
  • shiba-inuShiba Inu(SHIB)$0.000014-2.88%
  • bitcoin-cashBitcoin Cash(BCH)$428.21-3.63%
  • leo-tokenLEO Token(LEO)$8.810.23%
  • hedera-hashgraphHedera(HBAR)$0.190548-4.46%
  • ToncoinToncoin(TON)$3.01-1.76%
  • moneroMonero(XMR)$402.931.43%
  • litecoinLitecoin(LTC)$96.39-2.71%
  • wethWETH(WETH)$2,555.79-1.11%
  • polkadotPolkadot(DOT)$4.58-3.62%
  • Yay StakeStone EtherYay StakeStone Ether(YAYSTONE)$2,671.07-2.84%
  • USDSUSDS(USDS)$1.000.00%
  • Bitget TokenBitget Token(BGB)$5.630.73%
  • Wrapped eETHWrapped eETH(WEETH)$2,728.00-0.94%
  • Binance Bridged USDT (BNB Smart Chain)Binance Bridged USDT (BNB Smart Chain)(BSC-USD)$1.000.40%
  • PengPeng(PENG)$0.60-13.59%
  • PepePepe(PEPE)$0.000014-8.03%
  • Pi NetworkPi Network(PI)$0.770.47%
  • Ethena USDeEthena USDe(USDE)$1.00-0.04%
  • MurasakiMurasaki(MURA)$4.32-12.46%
  • Black PhoenixBlack Phoenix(BPX)$3.351,000.00%
  • WhiteBIT CoinWhiteBIT Coin(WBT)$31.87-0.06%
slot machine games real money