- DNS attack on Aerodrome and Velodrome results in a loss of $700,000 for users due to phishing pages.
- Domains were compromised through registrar NameSilo, redirecting users to malicious sites.
- Decentralized dApps and MetaDEX remained unaffected despite the breach.
- Security partners quickly contained the attack, enhancing user safety.
- Aerodrome and Velodrome plan domain migration to prevent future incidents.
Aerodrome and Velodrome Publish Report on NameSilo Breach
In a significant development within the cryptocurrency sector, decentralized exchanges Aerodrome and Velodrome have reported a major DNS breach that resulted in substantial financial losses. On November 21st, both platforms experienced a hijack of their centralized domains, redirecting users to phishing pages. Despite this setback, decentralized applications (dApps) and the MetaDEX platform remained fully operational.
The Attack: How It Happened
According to official statements from both exchanges, internal compromise at registrar NameSilo was identified as the root cause behind this breach. Attackers bypassed multi-signature controls in the 3DNS system and removed DNSSEC security measures. This allowed them to redirect domains towards harmful content.
“DNSSEC was removed from both domains,” stated an official report from the exchanges. Fortunately, security partners including Blockaid, 0xGroomLake, SEAL, and FTI Consulting acted swiftly to localize the attack.
Rapid Response and Mitigation Efforts
The quick response by security teams was crucial in limiting damages. Within two minutes of detecting malicious transactions, vital wallets like Metamask and Coinbase Wallet started showing alerts. Users were urged immediately to cease any interaction with web-based services until further notice.
The containment process took less than four hours after implementing necessary fixes. However, approximately $700,000 was lost through signed phishing transactions before complete blockades were established.
Future Measures: Domain Migration Plans
To safeguard against future incidents like these DNS attacks on Aerodrome and Velodrome’s infrastructure plans are already underway for domain migrations. Collaborating with leading corporate registrars ensures better protection going forward while also exploring options such as launching fully autonomous dApps behind firewalls or private networks with dedicated RPC endpoints.
Additionally — Aero Foundation alongside Velo Foundation — announced grant programs tailored towards compensating affected users who signed harmful transactions during this period.
Market Reaction: Token Performance & Future Outlook
Following news about these breaches token prices experienced fluctuations; notably Aerodrome Finance’s AERO saw a decline by about 5.93% over one day lagging behind broader market trends. Despite past vulnerabilities highlighted throughout previous incidents including last year’s frontend compromises systemic risks inherent within centralized DNS infrastructures remain prevalent challenges facing DeFi platforms today yet innovative solutions continue emerging paving way towards more secure decentralized financial ecosystems ultimately benefiting global communities long term outlook remains optimistic fueled partly recent investments such as those made earlier year via Coinbase Ventures Base Ecosystem Fund which sparked significant growth across various projects involved within space
Overall impacts extend beyond immediate losses incurred during event itself shedding light upon broader implications surrounding cybersecurity resilience necessity ongoing vigilance proactive strategies mitigating potential threats fostering safer environments innovation thriving amidst evolving landscape blockchain technology continues revolutionizing industries worldwide unlocking unprecedented opportunities prosperity shared globally alike
