create account

DNS Hijack | Curve.Fi on Target! by idiosyncratic1

View this thread on: hive.blogpeakd.comecency.com
· @idiosyncratic1 ·
$25.55
DNS Hijack | Curve.Fi on Target!
Curve is a decentralized exchange that is used by millions of crypto investors daily. The platform enables investors to exchange their stablecoins and other cryptocurrencies with their wrapped versions in the liquidity pools. 

![curve crypto dns hijack.png](https://images.hive.blog/DQmZF8nQZkWVUhdyu6Ht5pZRCaUm8krnGPwqyUQ8EUuU9SJ/curve%20crypto%20dns%20hijack.png)

With Aave, Curve has $6B TVL on several blockchains including Ethereum, Avalanche and Layer 2 Polygon, Arbitrum, and Optimism. Frankly, having Aave and Curve on your L2 or Mainnet makes it a worthy project in the eyes of many people. Both projects are **prestigious** to collaborate with!

![image.png](https://images.hive.blog/DQmZeLw6s4NJTRZfFajJJSDzc4uxjRj1ERMXMgvXP3tL36A/image.png)

Owning 5th highest TVL on it, Curve suffered a DNS hijack a couple of hours ago. Let's see what happened and why did it take place.

### DNS Vulnerability - Frontent Attack
Hackers were able to manipulate the DNS service and they were able to control curve.fi domain. When they were able to manipulate it, the contract address was changed by their own wallet:

![image.png](https://images.hive.blog/DQmcMzJ6U3STYbVxE8huMXZ5CoqtNEpvmiExn4SpkX5r89k/image.png)

As you can see above, this contract address was the one that the hackers gathered the money from investors.

According to [Decrypt](https://decrypt.co/107120/stablecoin-trading-platform-curve-suffers-frontend-attack-report), so far $570K worth of Ethereum is stolen. Thanks to blockchain, it is relatively easy to track the transactions of the known wallet addresses.

![image.png](https://images.hive.blog/DQmZAddorNdb5JiuKuPFZFUdBjFEYDoEgTMA9ZAQZhXjnxL/image.png) 

A Twitter user, [pepe_de_niro](https://twitter.com/pepe_de_niro/status/1557130713866141697), provided the traffic of the wallet. As you can see above, Tornado Cash, Binance and some personal Ethereum wallets are included. 

Yesterday we talked about [Tornado Cash Sanctions and Blacklists](https://leofinance.io/@idiosyncratic1/sanctions-on-tornado-cash-who-s-next) and the next day it happened 😅 Knowing this fact, Hackers tried to use [FixedFloat](https://twitter.com/FixedFloat/status/1557116267378708481) but the service provider took an immediate action to freeze the funds.


![image.png](https://images.hive.blog/DQmRx8TFi7QbQ4qdhW1PmpL5zBGQGTP8t9CYSsXftByP3ti/image.png)

Question: Is it the good side of **CeFi**?
You decide 😉

### Web3 in Under Attack
I coined the word **Hackaverse** in which blockchain-based projects are hacked or, at least, stress-tested by malicious attacks. Using **GoDaddy** for DNS, Curve was hunted down from its weak side.

Imagine you lose your money while you are using Curve. Let's be honest, it is gone. While De-Fi services are still dealing with such weaknesses, it is too hard to rely on them.

![image.png](https://images.hive.blog/DQmcFbfX57odareNH4Mymc7MEhLWTXFwVtdfpo6jSk8REtN/image.png) 

[Mobile Wallets, DNS, Bridges, and Tokenomics...](https://leofinance.io/@idiosyncratic1/crypto-wallet-vulnerability-or-first-solana-then-near) All these cases have one thing in common: Suffering people... What makes Hive unique is the security of the wallet. I do not feel that I need a Ledger to secure my Hive / HBD or Hive tokens. Just count how many Hive private keys you have for your single account and the number of frontends you can use to access your funds. 

### Hackaverse mode: ON
How many hack, exploit and sanction news have we seen in a month? I think the ecosystem is putting huge efforts to safely pass through the bear market and the depressing atmosphere in cryptoworld. 

FUD lost its value as the market does not actually react to it as before. Contrarily, hacking is not something negligible; it is devastating for a blockchain-based ecosystem. During this bear market, I'm not going to dive into newly developed apps, wallets or products that I need to download to access. 

Better to stay on the safe side. Even the Curve team (managing $6B TVL) may have hilarious **"mistakes"**. However, tiny mistakes may end up losing your whole savings in a couple of minutes.

Stay Safe ✌🏼 

Posted Using [LeoFinance <sup>Beta</sup>](https://leofinance.io/@idiosyncratic1/dns-hijack-or-curve-fi-on-target)
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , and 183 others
👎  
properties (23)
authoridiosyncratic1
permlinkdns-hijack-or-curve-fi-on-target
categoryhive-167922
json_metadata{"app":"leofinance/0.2","format":"markdown","tags":["proofofbrain","ctp","crypto","curve","hack","vyb","neoxian","cent","leofinance"],"canonical_url":"https://leofinance.io/@idiosyncratic1/dns-hijack-or-curve-fi-on-target","links":["https://decrypt.co/107120/stablecoin-trading-platform-curve-suffers-frontend-attack-report","https://twitter.com/pepe_de_niro/status/1557130713866141697","https://leofinance.io/@idiosyncratic1/sanctions-on-tornado-cash-who-s-next","https://twitter.com/FixedFloat/status/1557116267378708481","https://leofinance.io/@idiosyncratic1/crypto-wallet-vulnerability-or-first-solana-then-near"],"image":["https://images.hive.blog/DQmZF8nQZkWVUhdyu6Ht5pZRCaUm8krnGPwqyUQ8EUuU9SJ/curve%20crypto%20dns%20hijack.png","https://images.hive.blog/DQmZeLw6s4NJTRZfFajJJSDzc4uxjRj1ERMXMgvXP3tL36A/image.png","https://images.hive.blog/DQmcMzJ6U3STYbVxE8huMXZ5CoqtNEpvmiExn4SpkX5r89k/image.png","https://images.hive.blog/DQmZAddorNdb5JiuKuPFZFUdBjFEYDoEgTMA9ZAQZhXjnxL/image.png","https://images.hive.blog/DQmRx8TFi7QbQ4qdhW1PmpL5zBGQGTP8t9CYSsXftByP3ti/image.png","https://images.hive.blog/DQmcFbfX57odareNH4Mymc7MEhLWTXFwVtdfpo6jSk8REtN/image.png"]}
created2022-08-09 23:22:15
last_update2022-08-09 23:22:15
depth0
children4
last_payout2022-08-16 23:22:15
cashout_time1969-12-31 23:59:59
total_payout_value12.810 HBD
curator_payout_value12.736 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length4,239
author_reputation497,306,936,152,539
root_title"DNS Hijack | Curve.Fi on Target!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id115,585,967
net_rshares32,353,539,097,013
author_curate_reward""
vote details (248)
@ecency ·
Your content has been **voted** as a part of [Encouragement program](https://ecency.com/ecency/@good-karma/encouragement-program-continues-82eafcd10a299). Keep up the good work! <br><br>Use Ecency daily to boost your growth on platform! <br><br><b>Support Ecency</b><br>[Vote for new Proposal](https://hivesigner.com/sign/update-proposal-votes?proposal_ids=%5B197%5D&approve=true)<br>[Delegate HP and earn more](https://ecency.com/hive-125125/@ecency/daily-100-curation-rewards)
properties (22)
authorecency
permlinkre-2022810t6527241z
categoryhive-167922
json_metadata{"tags":["ecency"],"app":"ecency/3.0.20-welcome","format":"markdown+html"}
created2022-08-10 06:52:09
last_update2022-08-10 06:52:09
depth1
children0
last_payout2022-08-17 06:52:09
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length478
author_reputation618,482,535,773,610
root_title"DNS Hijack | Curve.Fi on Target!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id115,593,207
net_rshares0
@mypathtofire ·
$0.03
My god, they are dropping like flies.
👍  
properties (23)
authormypathtofire
permlinkre-idiosyncratic1-2022810t13346780z
categoryhive-167922
json_metadata{"tags":["hive-167922","proofofbrain","ctp","crypto","curve","hack","vyb","neoxian","cent","leofinance"],"app":"ecency/3.0.32-mobile","format":"markdown+html"}
created2022-08-09 23:33:48
last_update2022-08-09 23:33:48
depth1
children1
last_payout2022-08-16 23:33:48
cashout_time1969-12-31 23:59:59
total_payout_value0.012 HBD
curator_payout_value0.013 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length37
author_reputation606,089,812,688,930
root_title"DNS Hijack | Curve.Fi on Target!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id115,586,152
net_rshares33,615,241,868
author_curate_reward""
vote details (1)
@idiosyncratic1 ·
Crazy times indeed 😅
properties (22)
authoridiosyncratic1
permlinkre-mypathtofire-2022810t3314720z
categoryhive-167922
json_metadata{"tags":["hive-167922","proofofbrain","ctp","crypto","curve","hack","vyb","neoxian","cent","leofinance"],"app":"ecency/3.0.32-mobile","format":"markdown+html"}
created2022-08-10 00:03:15
last_update2022-08-10 00:03:15
depth2
children0
last_payout2022-08-17 00:03:15
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length20
author_reputation497,306,936,152,539
root_title"DNS Hijack | Curve.Fi on Target!"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id115,586,642
net_rshares0
@poshtoken ·
$0.08
https://twitter.com/idiosyncratic1_/status/1557147843114196993
<sub> The rewards earned on this comment will go directly to the people( @idiosyncratic1 ) sharing the post on Twitter as long as they are registered with @poshtoken. Sign up at https://hiveposh.com.</sub>
👍  
properties (23)
authorposhtoken
permlinkre-idiosyncratic1-dns-hijack-or-curve-fi-on-target-6583
categoryhive-167922
json_metadata"{"app":"Poshtoken 0.0.1","payoutToUser":["idiosyncratic1"]}"
created2022-08-09 23:41:09
last_update2022-08-09 23:41:09
depth1
children0
last_payout2022-08-16 23:41:09
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.083 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length269
author_reputation5,338,285,143,995,377
root_title"DNS Hijack | Curve.Fi on Target!"
beneficiaries
0.
accountreward.app
weight10,000
max_accepted_payout1,000,000.000 HBD
percent_hbd0
post_id115,586,284
net_rshares211,486,604,663
author_curate_reward""
vote details (1)