Curve CRV Demonstrates Resilience: Swift Action Thwarts DNS Phishing Attempt
Curve Finance (CRV), a leading decentralized finance (DeFi) protocol, successfully mitigated a DNS phishing attack targeting its curve.fi domain. The team promptly redirected users to the secure curve.finance domain and issued alerts via social media channels. Wallet providers including Phantom implemented protective measures by blocking the fraudulent site with security warnings. Crucially, the protocol’s infrastructure and user funds remained uncompromised—the attack was limited to DNS LAYER vulnerabilities.
The attack methodology involved domain record hijacking to redirect users to malicious IP addresses, reminiscent of a similar 2022 incident. Curve’s rapid response highlights the DeFi sector’s improving security capabilities against sophisticated threats. The incident did not affect any cryptocurrency exchanges or involve additional digital assets beyond the DNS compromise.