Résumé
On May 12, 2025, attackers hijacked Curve Finance's primary domain, curve.fi, at the registrar and DNS level and pointed visitors at a wallet-draining clone of the site. Curve's smart contracts and on-chain funds were never touched; this was a Web2 attack on the domain, the soft underbelly that no Solidity audit can protect. The nameservers for curve.fi were swapped to attacker-controlled infrastructure at the registrar (iwantmyname, the same registrar implicated in Curve's 2022 hijack), and the clone prompted users to approve malicious token transactions. On-chain analysts estimated user losses around $520,000, most of it taken in the first ninety minutes. Curve repointed the domain to neutral nameservers, then permanently migrated to curve.finance and signaled a move toward decentralized (ENS) hosting.
Comment le corriger
- Immediately repoint the domain to neutral nameservers to stop serving the malicious clone, then force-rotate registrar credentials and audit the account for rogue contacts or pending transfers.
- Push warnings through every channel and coordinate with wallet and security vendors (Blockaid, Phantom) to blocklist the malicious domain.
- Tell users to revoke any token approvals granted while the clone was live (revoke.cash or an explorer's approvals view).
- Migrate to a clean, locked domain if the original cannot be quickly and safely recovered, as Curve did with curve.finance.
Comment l’éviter dans votre code
- Lock the domain at the registrar and registry (clientTransferProhibited and registry lock), enable DNSSEC, and require hardware-key (FIDO2) 2FA on registrar, DNS, CDN, and email accounts.
- Choose a registrar that supports change notifications and anti-social-engineering controls; Curve's repeat hits through the same registrar show registrar choice is a real risk variable.
- Serve the dApp from content-addressed hosting (ENS plus IPFS) so the canonical entry point does not depend on one mutable DNS record.
- Monitor DNS records and certificate-transparency logs for unexpected changes; the protocols that survived these waves caught the takeover through monitoring.
- On the user side, verify spender contract addresses, bookmark canonical URLs, and use hardware wallets with clear-signing so a malicious approval cannot be blind-signed.
Détails de l’avis
How it happened
A frontend hijack leaves the on-chain protocol intact but replaces the website users actually visit. The attacker gained control of Curve's domain at the registrar level and altered its DNS delegation, swapping the Cloudflare nameservers to ones they controlled. Curve's founder Michael Egorov said the registrar effectively transferred control without any email notification, and that Curve saw no sign of a compromise of its own login credentials, pointing to a registrar-side failure rather than a phish of Curve's account (the precise root cause was still under investigation). The cloned site was a near-static decoy: it did not work as a real interface, it simply asked visitors to connect a wallet and sign token approvals and transfers that routed funds to the attacker, the classic approval-phishing drain run by a wallet drainer.
The damage
On-chain investigators (notably rotki's Lefteris Karapetsas) traced roughly $520,000 moved by the attacker within about ninety minutes, around $500,000 as ETH plus about $20,000 in other tokens; several outlets reported the incident without any official figure, so treat the number as a best on-chain estimate rather than a Curve-confirmed total. The losses came from individual users who interacted with the clone during the redirect window; Curve's treasury and protocol funds were unaffected. Curve, plus security firms Blockaid and Cyvers and wallets like Phantom, warned users and blocklisted the malicious domain, which limited the exposure window even though the early minutes were the costly ones.
A repeat, not a one-off
This was Curve's second domain hijack. In August 2022, curve.fi was DNS-hijacked through a compromised nameserver and drained about $570,000, also tied to the registrar iwantmyname. It also came during a bad week: on May 5, 2025, Curve's X account was separately compromised to push a fake airdrop link. None of this is unique to Curve; it is the dominant way DeFi frontends get attacked, because the contracts are hard targets while the Web2 domain is a single mutable record. The same pattern has hit CoW Swap, Compound, Ambient, KyberSwap, and others, catalogued in Stateward's DeFi frontend and DNS hijack overview. Note this is entirely distinct from the 2023 Curve Vyper reentrancy hack, which was a roughly $70 million smart-contract bug, not a DNS event.
Why it matters
The protocol can be flawless and users still lose money if the front door is a single DNS record at a registrar with weak controls. The fix is twofold. Operators must harden the registrar (registry transfer lock, DNSSEC, hardware-key 2FA) and ideally serve the interface from content-addressed hosting (ENS plus IPFS) so the entry point is not one mutable record, which is exactly why Curve moved to curve.finance and toward ENS. Users must learn to verify the contract they are signing rather than trusting the UI, and rely on hardware wallets with clear-signing and transaction simulation so a blind approval cannot silently grant an unlimited allowance.
Références
- https://news.curve.finance/curve-domain-incident/
- https://cointelegraph.com/news/curve-finance-warns-dns-hijacked-again
- https://www.theblock.co/post/354067/curve-finances-front-end-targeted-in-dns-attack-on-website
- https://decrypt.co/319414/curve-finance-dns-record-attack
- https://domainnamewire.com/2025/05/13/domain-exploit-at-curve-finance-triggers-wallet-drains-registrar-intervenes/
Vulnérabilités liées
Tout Web3 →- HIGHWEB3-FRONTEND-DNS-HIJACK-2022
A frontend hijack leaves the on-chain contracts untouched but replaces the Web2 surface serving the dApp UI with a wallet-drainer clone, so no Solidity audit can catch it. The recurring pattern: attackers take over the domain registrar or DNS provider account (or a CDN/tag-manager account), repoint the domain to a cloned site, and prompt visitors to sign malicious token approvals, EIP-2612 permit signatures, or transfers. Curve Finance was hit twice: on August 9-10, 2022 its curve.fi domain was DNS-hijacked via a compromised nameserver and drained ~$570K in USDC/DAI; and again around May 12, 2025 at the registrar level, after which Curve permanently migrated to curve.finance and announced an ENS move (Convex Finance and Resupply, which depend on Curve's data feeds, suffered dependency-driven outages but were not themselves compromised). In July 2024 a mass wave hit DeFi domains registered through Squarespace, whose forced migration off Google Domains stripped 2FA: Compound's frontend redirected to an Inferno Drainer clone and 100+ protocols were exposed (Celer blocked its takeover via domain monitoring). Ambient Finance's domain was hijacked through stolen registrar credentials on October 17, 2024. Most recently, on April 14, 2026 attackers used forged identity documents to social-engineer the registrar into handing over DNS control of CoW Swap's swap.cow.fi and cow.fi domains, redirecting users to a pixel-perfect drainer clone for about 90 minutes; over $1M was taken in roughly three hours, including 219 ETH (~$750K) from a single wallet, while CoW's contracts, backend APIs, and solver network were untouched. The same bucket includes CDN-account injections (KyberSwap's September 2022 Cloudflare/Google Tag Manager compromise, ~$265K) and BGP route hijacks that swap signed bundles for drainer code.
- CRITICALWEB3-KELPDAO-LAYERZERO-2026
On April 18, 2026, North Korea's Lazarus Group drained about 116,500 rsETH (roughly $292 million) from KelpDAO's LayerZero-based bridge, the largest DeFi exploit of the year. No smart contract was broken; the contracts did exactly what they were written to do. The attack was against the bridge's off-chain verification. rsETH's LayerZero channel was configured to trust a single verifier (a 1-of-1 DVN), so the attackers compromised LayerZero's internal RPC nodes, knocked out the honest external node with a denial-of-service flood, and forced that single verifier to attest to a cross-chain message that never really happened. The Ethereum side then released unbacked rsETH from escrow, leaving wrapped rsETH stranded across more than twenty chains and triggering a bank-run across DeFi.
- CRITICALWEB3-KILOEX-2025
On April 14, 2025 the perpetuals DEX KiloEx lost about $7.5 million across BNB Chain, Base, opBNB, and Taiko to what was reported as oracle price manipulation but was really an access-control failure. KiloEx's price feed (KiloPriceFeed.setPrices) was meant to be reachable only through a keeper-gated call chain, but the top-level MinimalForwarder.execute function was publicly callable and validated an attacker-supplied signature against attacker-supplied data, letting anyone forge a trusted call that reached setPrices and write an arbitrary price. The attacker set a market price far below true value, opened a leveraged position, then set the price far above value and closed it in the same flow, extracting fabricated profit from the vault; the sequence was repeated across all four chains, with a single transaction netting $3.12M. Reporting that framed it as flash-loan oracle manipulation was imprecise: no market liquidity was moved, the price was simply written directly through the unprotected forwarder. After KiloEx offered a 10% (~$750K) whitehat bounty and no legal action, the attacker returned essentially all of the funds by April 18, 2025.
- CRITICALWEB3-BYBIT-2025
On 21 February 2025, the crypto exchange Bybit lost about $1.5 billion in ether, the largest hack in history, to North Korea's Lazarus Group. Bybit had done what custody best-practice prescribes: the funds sat in a cold wallet behind a multisig requiring several human signers. The attackers beat it anyway, not by stealing keys but by tampering with what the signers saw. Weeks earlier they had compromised a developer at Safe, the multisig-wallet provider, and slipped malicious code into the Safe web app, so that when Bybit's executives reviewed a routine transfer, the screen showed a legitimate transaction while their hardware wallets were actually signing a malicious one that handed the wallet to the attacker. It is the defining lesson that a multisig is only as trustworthy as the screen you approve it on, and that blind-signing is the modern crypto catastrophe.
- CRITICALWEB3-RADIANT-2024
On October 16, 2024, the cross-chain lending protocol Radiant Capital lost roughly $50M (about $53M across Arbitrum and BSC) after attackers compromised the devices of at least three of its multisig signers. Initial access began September 11, 2024 via a Telegram message spoofing a trusted former contractor, delivering a ZIP with a decoy PDF that was actually a macOS application carrying INLETDRIFT backdoor malware. The malware sat between the signers' browsers and their hardware wallets, so the Safe (Gnosis) UI and Tenderly simulations displayed correct data while the signers blind-signed a malicious transferOwnership() call on the LendingPoolAddressesProvider contract; the 3-of-11 threshold was met and the attacker then upgraded the pools to a malicious implementation and drained them. Mandiant assessed with high confidence the attack was conducted by North Korea-linked UNC4736 (aka Citrine Sleet/AppleJeus), part of the Lazarus cluster. Funds were not recovered and the protocol later wound down.
- CRITICALWEB3-WAZIRX-2024
On July 18, 2024 Indian exchange WazirX lost approximately $230M (about $234.9M) from a Safe (Gnosis) 4-of-6 multisig wallet held under a custody arrangement with Liminal (five WazirX keys plus one Liminal key). The attack was a blind-signing exploit: signers reviewed benign transaction details in the manipulated Liminal interface while the payload actually signed differed, authorizing a delegatecall (function selector 0x804e1f0a) that overwrote slot0 of the Safe proxy and repointed its implementation to an attacker-controlled contract (0xef279c2ab14960aa319008cbea384b9f8ac35fc6). Once the proxy pointed to attacker logic the wallet was fully controlled without further keys, and it was drained. The theft was attributed to North Korea's Lazarus Group, later confirmed in a joint statement by the US, South Korea and Japan in January 2025. Funds were laundered via Tornado Cash; victims are being repaid through a court-approved restructuring (resumed October 2025, BitGo custody) rather than direct recovery.