• About
  • FAQ
  • Contact Us
Newsletter
Crypto News
Advertisement
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
No Result
View All Result
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
No Result
View All Result
Crypto News
No Result
View All Result
Home Analysis

Curve Finance Hit by DNS Record Attack, Warns Users to Avoid Main Site

admin by admin
May 13, 2025
in Analysis
0
Curve Finance Hit by DNS Record Attack, Warns Users to Avoid Main Site
190
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

In brief

  • Curve Finance’s front-end website suffered a DNS compromise where attackers redirected users to a malicious site.
  • The attack involved manipulating DNS records to point to a fraudulent site mimicking Curve’s interface with malicious scripts designed to trick users into approving token transfers.
  • This isn’t Curve Finance’s first security incident. They experienced a similar DNS hijack in 2022 resulting in $570,000 in losses, and faced another exploit in 2023 involving Vyper programming vulnerabilities with estimated losses of $24 million.

Decentralized protocol Curve Finance confirmed Tuesday that its front-end website was compromised, with attackers redirecting users to a fake site.

“The DNS incident involving Curve Finance reflects a broader issue across the industry,” the project told Decrypt. “In recent weeks, there has been a noticeable increase in attacks targeting the infrastructure of various crypto projects.”

The exploit redirected traffic to a malicious IP, the protocol said on social media. “User funds are safe. Curve smart contracts remain secure,” it added.

The incident was first discovered on Monday afternoon, after which Curve Finance issued a preliminary response.

While all smart contracts are safe, the domain name points to a malicious site which can drain your wallet!

We are investigating and working on recovering the access.

No sign of a compromise on our side https://t.co/YUmwtwt5PH

— Curve Finance (@CurveFinance) May 12, 2025

Curve Finance later said the breach was “strictly limited to the DNS layer” and did not compromise its core infrastructure.

Its security team promptly isolated the issue, initiated an investigation, and engaged with their domain registrar and security partners to address the situation, the project said.

Security measures were in place “long before the incident,” the protocol added.

What happened?

According to Curve Finance, attackers manipulated the DNS records to point to an IP address under their control. A DNS record connects a domain name to details like an IP address, helping direct internet traffic.

The fraudulent site, which mirrored Curve’s interface, reportedly contained malicious scripts aimed at tricking users into approving token transfers to the attackers.

Related articles

Bitcoin Options Open Interest Spikes to Record High as Traders Target 6K

Bitcoin Options Open Interest Spikes to Record High as Traders Target $116K

May 22, 2025
‘Orgy of Corruption’: Senators Slam Trump Crypto Dinner, Demand Info on Attendees

‘Orgy of Corruption’: Senators Slam Trump Crypto Dinner, Demand Info on Attendees

May 22, 2025

“DNS exploits are a form of social engineering at the infrastructure level. Attackers compromise the domain name system,” Meir Dolev, co-founder and CTO of blockchain security firm Cyvers, told Decrypt.

If a site’s mapping changes due to stolen credentials or a registrar’s vulnerability, users may be redirected to harmful servers without realizing it.

“These cloned sites can prompt users to connect wallets and approve transactions that drain funds,” Dolev explained. “It’s particularly dangerous because the average user can’t easily tell the difference—they still see the correct URL.”

The attack doesn’t breach the protocol’s blockchain, but rather “exploits the trust layer” between the user and a decentralized app’s interface.

“So long as users interact with Curve directly via verified contract addresses, their funds are likely unaffected,” Dolev noted.

Hacking history

This isn’t the first time Curve has been hit.

Back in 2022, Curve Finance suffered a DNS hijack where attackers redirected users from its legitimate domain to a malicious site, resulting in approximately $570,000 in losses.

Following the attack, Curve advised users to revoke any suspicious approvals and proposed migrating to the Ethereum Name Service (ENS) to mitigate future vulnerabilities.

A year later, Curve Finance faced another exploit involving some Vyper programming language versions and the CRV/ETH pool.

The loss across affected DeFi projects was estimated at $24 million at the time.

Edited by Stacy Elliott.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.





#Curve #Finance #Hit #DNS #Record #Attack #Warns #Users #Avoid #Main #Site

Tags: attackAvoidCurveDNSfinancehitmainrecordSiteusersWarns
Share76Tweet48

Related Posts

Bitcoin Options Open Interest Spikes to Record High as Traders Target 6K

Bitcoin Options Open Interest Spikes to Record High as Traders Target $116K

by admin
May 22, 2025
0

In brief Open interest for Bitcoin options most recently stood at an all-time high of around $65 billion. An increase...

‘Orgy of Corruption’: Senators Slam Trump Crypto Dinner, Demand Info on Attendees

‘Orgy of Corruption’: Senators Slam Trump Crypto Dinner, Demand Info on Attendees

by admin
May 22, 2025
0

Congressional Democrats unloaded on President Donald Trump’s plans to dine with top holders of his meme coin this evening, demanding...

BTC hits ATH, InfoFi battle begins, Texas passes BTC bill

BTC hits ATH, InfoFi battle begins, Texas passes BTC bill

by admin
May 22, 2025
0

BTC hits ATH, InfoFi battle begins, Texas passes BTC billBTC hits ATH, InfoFi battle begins, Texas passes BTC bill FOMO...

Bitcoin Pizza Day, 15 Years Later: Here’s How Much Those Pies Are Worth Now

Bitcoin Pizza Day, 15 Years Later: Here’s How Much Those Pies Are Worth Now

by admin
May 22, 2025
0

In brief Today celebrates Bitcoin Pizza Day, when a man spent 10,000 BTC to buy two pizzas in May 2010....

Ethereum, Solana and Dogecoin Jump as Bitcoin Sets Another Record Price

Ethereum, Solana and Dogecoin Jump as Bitcoin Sets Another Record Price

by admin
May 22, 2025
0

Bitcoin keeps rising Thursday, inching up to yet another all-time high mark after beating its four-month-old record on Wednesday. And...

Load More
  • Trending
  • Comments
  • Latest
Bitcoin and Ethereum Stuck in Range, DOGE and XRP Gain

Bitcoin and Ethereum Stuck in Range, DOGE and XRP Gain

April 25, 2025
Saylor says Warren Buffett’s Berkshire Hathaway is Bitcoin of 20th century – Deep Insight

Saylor says Warren Buffett’s Berkshire Hathaway is Bitcoin of 20th century – Deep Insight

May 7, 2025
Amazon CEO on Crypto and NFTs, EPNS to Expand Beyond Ethereum + More News

Amazon CEO on Crypto and NFTs, EPNS to Expand Beyond Ethereum + More News

April 25, 2025
Why DeFi agents need a private brain

Why DeFi agents need a private brain

May 4, 2025
US Commodities Regulator Beefs Up Bitcoin Futures Review

US Commodities Regulator Beefs Up Bitcoin Futures Review

0
Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0
India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0
Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: 5.55

Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55

0
US tourist drugged by fake Uber driver and robbed of 3K BTC — Report

US tourist drugged by fake Uber driver and robbed of $123K BTC — Report

May 22, 2025
Bitcoin Options Open Interest Spikes to Record High as Traders Target 6K

Bitcoin Options Open Interest Spikes to Record High as Traders Target $116K

May 22, 2025
Centrifuge Expands Tokenized Assets to Solana Starting With 0M Treasury Fund

Centrifuge Expands Tokenized Assets to Solana Starting With $400M Treasury Fund

May 22, 2025
Active DeFi loans hit all-time high at .7B as TVL nears pre-tariff levels

Active DeFi loans hit all-time high at $23.7B as TVL nears pre-tariff levels

May 22, 2025
  • About
  • FAQ
  • Contact Us
Call us: +1 23456 JEG THEME

© 2025 Btc04.com

No Result
View All Result
  • Home
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
  • Contact Us

© 2025 Btc04.com