Aerodrome Finance, the leading decentralized exchange on the Base network, confirmed it is investigating a suspected DNS hijacking attack that compromisedAerodrome Finance, the leading decentralized exchange on the Base network, confirmed it is investigating a suspected DNS hijacking attack that compromised

Base’s Top DEX Aerodrome Hit by a Suspected Frontend Security Breach

4 min read

Aerodrome Finance, the leading decentralized exchange on the Base network, confirmed it is investigating a suspected DNS hijacking attack that compromised its centralized domains.

The protocol warned users to avoid accessing its primary .finance and .box domains and instead use two secure decentralized mirrors hosted on ENS infrastructure.

The attack unfolded rapidly, with affected users reporting malicious signature requests designed to drain multiple assets, including NFTs, ETH, and USDC, through unlimited approval prompts.

While the team maintains that all smart contracts remain secure, the frontend compromise exposed users to sophisticated phishing attempts that could have drained wallets for those who weren’t carefully monitoring transaction approvals.

DNS Hijacking Forces Emergency Protocol Lockdown

Aerodrome’s investigation began when the team detected unusual activity on its primary domain infrastructure approximately six hours before issuing public warnings.

The protocol immediately flagged its domain provider, Box Domains, as potentially compromised and urged the service to reach out urgently.

Within hours, the team confirmed that both centralized domains, .finance and .box, had been hijacked and remained under attacker control.

The protocol responded by shutting down access to all primary URLs while establishing two verified safe alternatives: aero.drome.eth.limo and aero.drome.eth.link.

These decentralized mirrors leverage the Ethereum Name Service, which operates independently of traditional DNS systems that are vulnerable to hijacking.

The team emphasized that smart contract security remained intact throughout the incident, containing the breach exclusively to frontend access points.

Sister protocol Velodrome faced similar threats, prompting its team to issue parallel warnings about domain security.

The coordinated nature of the warnings suggested that attackers may have systematically targeted Box Domains’ infrastructure to compromise multiple DeFi platforms simultaneously.

Users Report Aggressive Multi-Asset Drain Attempts

One affected user described encountering the malicious interface before official warnings circulated, detailing how the compromised site deployed a deceptive two-stage attack.

The hijacked frontend first requested what appeared to be a harmless signature containing only the number “1,” establishing initial wallet connection.

Immediately after this seemingly innocuous request, the interface triggered an unlimited number of approval prompts for NFTs, ETH, USDC, and WETH.

It asked for a simple signature, then instantly tried unlimited approvals to drain NFTs, ETH, and USDC,” the user reported. “If you weren’t paying attention, you could’ve lost everything.

The victim documented the attack through screenshots and video recordings, capturing the progression from initial signature request through multiple drain attempts.

Their investigation, conducted with AI assistance, examined browser configurations, extensions, DNS settings, and RPC endpoints before concluding that the attack pattern aligned with DNS hijacking methodology.

Another community member shared an experience with a separate, draining incident recently, describing themselves as a seasoned veteran and full-stack developer who still fell victim to sophisticated attacks.

Despite technical expertise, the user lost significant funds and spent 3 days developing a Jito bundle-based script to recover roughly 10-15% of the stolen assets through on-chain stealth operations.

October Records Lowest Crypto Hack Losses of the Year

The Aerodrome incident emerged during October’s unexpected security milestone, as the crypto market experienced its lowest monthly hack losses of the year.

Data from blockchain security firm PeckShield shows only $18.18 million was stolen across 15 separate incidents, representing a steep 85.7% decline from September’s $127.06 million.

Without the late-month Garden Finance exploit, total losses would have hovered near $7.18 million, the lowest single-month value since early 2023.

The largest incidents occurred at Garden Finance, Typus Finance, and Abracadabra, which collectively accounted for $16.2 million of total stolen funds.

Garden Finance, a Bitcoin peer-to-peer protocol, disclosed on October 30 that it had been exploited for more than $10 million after one of its solvers was compromised, with the breach affecting only the solver’s own inventory.

Typus Finance suffered an oracle manipulation attack on October 15 that drained roughly $3.4 million from its liquidity pools, traced to a flaw in one of its TLP contracts that caused the project’s native token to drop about 35%.

DeFi lending platform Abracadabra endured its third exploit since launch around the same time, resulting in roughly $1.8 million in MIM stablecoin losses after hackers bypassed solvency checks through a smart contract vulnerability.

Market Opportunity
TOP Network Logo
TOP Network Price(TOP)
$0.000096
$0.000096$0.000096
0.00%
USD
TOP Network (TOP) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Regulatory Clarity Could Drive 40% of Americans to Adopt DeFi Protocols, Survey Shows

Regulatory Clarity Could Drive 40% of Americans to Adopt DeFi Protocols, Survey Shows

Over 40% of Americans express willingness to use decentralized finance (DeFi) protocols once regulatory clarity on crypto privacy emerges, according to a recent survey from crypto advocacy organization the DeFi Education Fund (DEF). The survey, released on September 18, revealed that many Americans feel frustrated with traditional financial institutions and seek greater control over their financial assets and data. Respondents believe DeFi innovations can deliver this change by providing affordability, equity, and consumer protection. The survey was conducted with Ipsos on KnowledgePanel and included supplementary in-depth interviews in the Bronx and Queens between August 18 and 21, polling 1,321 US adults. Survey Results Show Americans Ready to Adopt DeFi Protocols The findings demonstrate that many Americans are curious about DeFi despite its early stage. 42% of Americans indicated they would likely try DeFi if proposed legislation becomes law (9% extremely/very likely and 33% somewhat likely). 84% said they would use it to “make purchases online,” while 78% would use it to “pay bills.” According to the survey, 77% would use DeFi protocols to “save money,” and 12% of Americans are “extremely” and “very” interested in learning about DeFi. Moreover, nearly 4 in 10 Americans believe that DeFi can address high transaction and service fees found in traditional finance (39%). Consistent with other probability-based sample surveys, the Ipsos x DEF research shows that almost 1 in 5 Americans (18%) have owned or used crypto at some point in their lifetime. Nearly a quarter of Americans (22%) said they’re interested in learning more about nontraditional forms of finance, such as blockchain, crypto, or decentralized finance.Source: DEF The research shows that more than half (56%) of Americans want to reclaim control of their finances. Americans are interested in having control over their money at all times, and many seek ways to send or receive money without intermediaries. One Bronx, NY resident shared his experience of needing to transfer money between accounts, but the bank required him to certify the transfer and visit in person because he couldn’t move the amount he needed remotely. He expressed frustration about the situation because “it was my money… I didn’t understand why I was given a hard time.“ More than half of surveyed Americans agree there should be a way to digitally send money to people without third-party involvement, and this number rises notably for foreign-born Americans (66%). The researchers concluded that Americans are interested in DeFi and believe DeFi can reduce friction points in today’s financial system. Regulatory Developments on DeFi Adoption in the U.S Last month, DeFi Education Fund called on the US Senate Banking Committee to rethink how it plans to regulate the decentralized finance industry after reviewing its recently published discussion draft on a key crypto market-structure bill. The response, signed on behalf of DeFi Education Fund (DEF) members including a16z Crypto, Uniswap Labs, and Paradigm, argued the Responsible Financial Innovation Act of 2025 (RFA) bill should be crafted in a more tech-neutral manner. The group also emphasized that crypto developers should be protected from “inappropriate regulation meant for intermediaries,” and that self-custody rights for all Americans are “essential.” The banking committee is now working on the discussion draft to help ensure it builds on the Digital Asset Market Clarity Act of 2025. The goal is to promote innovation in the $162 billion DeFi industry without compromising consumer protections or financial stability. On September 5, US Federal Reserve Governor Christopher Waller said there was “nothing to be afraid of” about crypto payments operating outside the traditional banking system. This statement has raised hopes among many that DeFi would soon become the new financial infrastructure for Americans and the world
Share
CryptoNews2025/09/18 21:29
Michael Burry’s Bitcoin Warning: Crypto Crash Could Drag Down Gold and Silver Markets

Michael Burry’s Bitcoin Warning: Crypto Crash Could Drag Down Gold and Silver Markets

TLDR Michael Burry warned that bitcoin’s drop below $73,000 may have forced institutions to sell up to $1 billion in gold and silver to cover crypto losses Burry
Share
Coincentral2026/02/04 15:28
Michelin-starred dimsum chain Tim Ho Wan doubles HK footprint with 10th store

Michelin-starred dimsum chain Tim Ho Wan doubles HK footprint with 10th store

For Tim Ho Wan’s chief executive officer Young Sheng Lee, the brand’s aggressive expansion in its home turf helped create a proven growth model that can be replicated
Share
Rappler2026/02/04 15:27