The post DNS Attack Knocks Top DEX Protocols Offline appeared on BitcoinEthereumNews.com. Crime The crypto industry just received another reminder that even the most decentralized applications still rely on centralized components — and that those weak points can be exploited. Key Takeaways: The attack on Aerodrome and Velodrome targeted their web domains, not their smart contracts or user funds. Both exchanges redirected users to decentralized front-ends after their centralized domains were compromised. The incident highlights that Web3 platforms remain vulnerable when Web2 infrastructure — like DNS — is exploited. Early Saturday, two of the largest decentralized exchanges in the Optimism Superchain ecosystem, Aerodrome on Base and Velodrome on Optimism, found themselves dealing with a threat that didn’t target their smart contracts or liquidity, but something far simpler: their websites. A Web2 Weak Link in a Web3 World The disruption didn’t emerge from on-chain vulnerabilities. Liquidity pools, staking contracts, and user funds remained fully secure. Instead, attackers took control of the Domain Name System layer, redirecting visitors from the real webpages to an imitation interface designed to trick users. Anyone typing the correct URLs could still land on a malicious landing page — a classic Web2 exploit wrapped around a Web3 service. To avoid exposing users to the malicious interface, both teams instructed traders to access the DEXs through decentralized mirrors and browser-safe alternatives rather than the official domain. The Hijack Was Brief — But Not Without Implications By Saturday afternoon, the fake front-end stopped loading. Velodrome briefly reached out publicly to its domain provider, My.box, before deleting the request. Neither team issued additional comments by publication time. Investigations are ongoing, and there is no confirmation yet on whether the attacker responsible for the weekend incident is the same type of threat actor from a similar event in November 2023, when a DNS compromise caused losses of more than $100,000, according to blockchain… The post DNS Attack Knocks Top DEX Protocols Offline appeared on BitcoinEthereumNews.com. Crime The crypto industry just received another reminder that even the most decentralized applications still rely on centralized components — and that those weak points can be exploited. Key Takeaways: The attack on Aerodrome and Velodrome targeted their web domains, not their smart contracts or user funds. Both exchanges redirected users to decentralized front-ends after their centralized domains were compromised. The incident highlights that Web3 platforms remain vulnerable when Web2 infrastructure — like DNS — is exploited. Early Saturday, two of the largest decentralized exchanges in the Optimism Superchain ecosystem, Aerodrome on Base and Velodrome on Optimism, found themselves dealing with a threat that didn’t target their smart contracts or liquidity, but something far simpler: their websites. A Web2 Weak Link in a Web3 World The disruption didn’t emerge from on-chain vulnerabilities. Liquidity pools, staking contracts, and user funds remained fully secure. Instead, attackers took control of the Domain Name System layer, redirecting visitors from the real webpages to an imitation interface designed to trick users. Anyone typing the correct URLs could still land on a malicious landing page — a classic Web2 exploit wrapped around a Web3 service. To avoid exposing users to the malicious interface, both teams instructed traders to access the DEXs through decentralized mirrors and browser-safe alternatives rather than the official domain. The Hijack Was Brief — But Not Without Implications By Saturday afternoon, the fake front-end stopped loading. Velodrome briefly reached out publicly to its domain provider, My.box, before deleting the request. Neither team issued additional comments by publication time. Investigations are ongoing, and there is no confirmation yet on whether the attacker responsible for the weekend incident is the same type of threat actor from a similar event in November 2023, when a DNS compromise caused losses of more than $100,000, according to blockchain…

DNS Attack Knocks Top DEX Protocols Offline

Crime

The crypto industry just received another reminder that even the most decentralized applications still rely on centralized components — and that those weak points can be exploited.

Key Takeaways:
  • The attack on Aerodrome and Velodrome targeted their web domains, not their smart contracts or user funds.
  • Both exchanges redirected users to decentralized front-ends after their centralized domains were compromised.
  • The incident highlights that Web3 platforms remain vulnerable when Web2 infrastructure — like DNS — is exploited.

Early Saturday, two of the largest decentralized exchanges in the Optimism Superchain ecosystem, Aerodrome on Base and Velodrome on Optimism, found themselves dealing with a threat that didn’t target their smart contracts or liquidity, but something far simpler: their websites.

The disruption didn’t emerge from on-chain vulnerabilities. Liquidity pools, staking contracts, and user funds remained fully secure. Instead, attackers took control of the Domain Name System layer, redirecting visitors from the real webpages to an imitation interface designed to trick users.

Anyone typing the correct URLs could still land on a malicious landing page — a classic Web2 exploit wrapped around a Web3 service.

To avoid exposing users to the malicious interface, both teams instructed traders to access the DEXs through decentralized mirrors and browser-safe alternatives rather than the official domain.

The Hijack Was Brief — But Not Without Implications

By Saturday afternoon, the fake front-end stopped loading. Velodrome briefly reached out publicly to its domain provider, My.box, before deleting the request. Neither team issued additional comments by publication time.

Investigations are ongoing, and there is no confirmation yet on whether the attacker responsible for the weekend incident is the same type of threat actor from a similar event in November 2023, when a DNS compromise caused losses of more than $100,000, according to blockchain tracer ZachXBT.

New Era, Old Attack Surface

Despite their dominance in the borrowing-and-lending markets of the Optimism Superchain, both platforms still depend on Web2 infrastructure — a core contradiction of the current decentralized economy. Smart contracts may be bulletproof, but if the entry point to them can be rerouted, attackers don’t need to touch the blockchain at all.

The Unification Backdrop

The attack arrives at a pivotal moment. Dromos Labs, the team behind Velodrome, has been preparing to merge the two major DEXs into a single entity called Aero.

Set to debut in Q2 2026, Aero will consolidate both platforms and their tokens into a single AERO token, designed to represent the full productive output of the unified exchange. The transition is expected to reduce fragmentation and increase liquidity — and now, likely, to demand hardened domain and access security.

Bigger Than a Weekend Hack

Neither Aerodrome nor Velodrome lost funds. Contract security held. But the event showed that centralized website infrastructure remains one of the most effective attack vectors against decentralized protocols.
To users, the takeaway may be uncomfortable but essential: even in Web3, the safest route to DeFi is not always the most convenient one.


The information provided in this article is for educational purposes only and does not constitute financial, investment, or trading advice. Coindoo.com does not endorse or recommend any specific investment strategy or cryptocurrency. Always conduct your own research and consult with a licensed financial advisor before making any investment decisions.

Author

Kosta joined the team in 2021 and quickly established himself with his thirst for knowledge, incredible dedication, and analytical thinking. He not only covers a wide range of current topics, but also writes excellent reviews, PR articles, and educational materials. His articles are also quoted by other news agencies.

Next article

Source: https://coindoo.com/dns-attack-knocks-top-dex-protocols-offline-smart-contracts-remain-secure/

Piyasa Fırsatı
TOP Network Logosu
TOP Network Fiyatı(TOP)
$0.000096
$0.000096$0.000096
0.00%
USD
TOP Network (TOP) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen [email protected] ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Sport.Fun’s FUN Token Sale Smashes 100% Target In One Day

Sport.Fun’s FUN Token Sale Smashes 100% Target In One Day

The post Sport.Fun’s FUN Token Sale Smashes 100% Target In One Day appeared on BitcoinEthereumNews.com. Stunning Success: Sport.Fun’s FUN Token Sale Smashes 100
Paylaş
BitcoinEthereumNews2025/12/18 11:04
A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release

A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release

The post A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release appeared on BitcoinEthereumNews.com. KPop Demon Hunters Netflix Everyone has wondered what may be the next step for KPop Demon Hunters as an IP, given its record-breaking success on Netflix. Now, the answer may be something exactly no one predicted. According to a new filing with the MPA, something called Debut: A KPop Demon Hunters Story has been rated PG by the ratings body. It’s listed alongside some other films, and this is obviously something that has not been publicly announced. A short film could be well, very short, a few minutes, and likely no more than ten. Even that might be pushing it. Using say, Pixar shorts as a reference, most are between 4 and 8 minutes. The original movie is an hour and 36 minutes. The “Debut” in the title indicates some sort of flashback, perhaps to when HUNTR/X first arrived on the scene before they blew up. Previously, director Maggie Kang has commented about how there were more backstory components that were supposed to be in the film that were cut, but hinted those could be explored in a sequel. But perhaps some may be put into a short here. I very much doubt those scenes were fully produced and simply cut, but perhaps they were finished up for this short film here. When would Debut: KPop Demon Hunters theoretically arrive? I’m not sure the other films on the list are much help. Dead of Winter is out in less than two weeks. Mother Mary does not have a release date. Ne Zha 2 came out earlier this year. I’ve only seen news stories saying The Perfect Gamble was supposed to come out in Q1 2025, but I’ve seen no evidence that it actually has. KPop Demon Hunters Netflix It could be sooner rather than later as Netflix looks to capitalize…
Paylaş
BitcoinEthereumNews2025/09/18 02:23
Ripple CEO Nails Bold RLUSD Call

Ripple CEO Nails Bold RLUSD Call

The post Ripple CEO Nails Bold RLUSD Call appeared on BitcoinEthereumNews.com. RLUSD’s stunning growth  Regulatory “gold standard” Ripple CEO Brad Garlinghouse
Paylaş
BitcoinEthereumNews2025/12/18 10:54