Curve Finance DNS Hijacked—Team Urges Users to Steer Clear of Compromised Site
DeFi’s latest security nightmare strikes again—this time snagging Curve Finance in a DNS record attack. Hackers rerouted traffic to a malicious clone site, prompting urgent warnings from the team.
How it happened: Attackers bypassed domain registrar safeguards (probably with a $5 wrench and some social engineering). The exploit mirrors last year’s $600M Poly Network heist—just without the polite hacker returning the funds.
Damage control: Curve’s devs are scrambling to lock down the breach while exchanges freeze suspicious withdrawals. Meanwhile, crypto Twitter alternates between ’DYOR’ lectures and ’bankers did this’ conspiracy threads.
Silver lining? Another masterclass in why your metamask seed phrase shouldn’t be ’password123’. The attack exposes DeFi’s lingering weak spot—the ancient DNS system that somehow still underpins web3’s future.