Curve Finance Hit by DNS Record Attack, Warns Users to Avoid Main Site
By: bitcoin ethereum news|2025/05/14 12:15:05
0
Share
In brief Curve Finance’s front-end website suffered a DNS compromise where attackers redirected users to a malicious site. The attack involved manipulating DNS records to point to a fraudulent site mimicking Curve’s interface with malicious scripts designed to trick users into approving token transfers. This isn’t Curve Finance’s first security incident. They experienced a similar DNS hijack in 2022 resulting in $570,000 in losses, and faced another exploit in 2023 involving Vyper programming vulnerabilities with estimated losses of $24 million. Decentralized protocol Curve Finance confirmed Tuesday that its front-end website was compromised, with attackers redirecting users to a fake site. “The DNS incident involving Curve Finance reflects a broader issue across the industry,” the project told Decrypt . “In recent weeks, there has been a noticeable increase in attacks targeting the infrastructure of various crypto projects.” The exploit redirected traffic to a malicious IP, the protocol said on social media. “User funds are safe. Curve smart contracts remain secure,” it added. The incident was first discovered on Monday afternoon, after which Curve Finance issued a preliminary response. While all smart contracts are safe, the domain name points to a malicious site which can drain your wallet! We are investigating and working on recovering the access. No sign of a compromise on our side https://t.co/YUmwtwt5PH — Curve Finance (@CurveFinance) May 12, 2025 Curve Finance later said the breach was “strictly limited to the DNS layer” and did not compromise its core infrastructure. Its security team promptly isolated the issue, initiated an investigation, and engaged with their domain registrar and security partners to address the situation, the project said. Security measures were in place “long before the incident,” the protocol added. What happened? According to Curve Finance, attackers manipulated the DNS records to point to an IP address under their control. A DNS record connects a domain name to details like an IP address, helping direct internet traffic. The fraudulent site, which mirrored Curve’s interface, reportedly contained malicious scripts aimed at tricking users into approving token transfers to the attackers. “DNS exploits are a form of social engineering at the infrastructure level. Attackers compromise the domain name system,” Meir Dolev, co-founder and CTO of blockchain security firm Cyvers, told Decrypt . If a site’s mapping changes due to stolen credentials or a registrar’s vulnerability, users may be redirected to harmful servers without realizing it. “These cloned sites can prompt users to connect wallets and approve transactions that drain funds,” Dolev explained. “It’s particularly dangerous because the average user can’t easily tell the difference—they still see the correct URL.” The attack doesn’t breach the protocol’s blockchain, but rather “exploits the trust layer” between the user and a decentralized app’s interface. “So long as users interact with Curve directly via verified contract addresses, their funds are likely unaffected,” Dolev noted. Hacking history This isn’t the first time Curve has been hit. Back in 2022, Curve Finance suffered a DNS hijack where attackers redirected users from its legitimate domain to a malicious site, resulting in approximately $570,000 in losses. Following the attack, Curve advised users to revoke any suspicious approvals and proposed migrating to the Ethereum Name Service (ENS) to mitigate future vulnerabilities. A year later, Curve Finance faced another exploit involving some Vyper programming language versions and the CRV/ETH pool. The loss across affected DeFi projects was estimated at $24 million at the time. Edited by Stacy Elliott. Daily Debrief Newsletter Start every day with the top news stories right now, plus original features, a podcast, videos and more. Source: https://decrypt.co/319414/curve-finance-dns-record-attack
You may also like

Revisiting RWA: Nearly 50,000 people's first on-chain transaction was not Bitcoin, but stock indices and crude oil
The narrative of RWA is not about traditional finance trying to capture crypto users, but rather crypto trying to capture traditional users.

Altcoin Price Outlook 2026: The Rotation Is Coming — Just Not the Way You Think
Bitcoin dominance at 58%, Fear & Greed at 39. If you think altcoin season is dead, you're reading the wrong signals. Here's what the data actually says about what comes next.

Oracle: The Second Battlefield Behind the Prediction Market War
By 2026, the oracle track has essentially evolved from the early "data pipeline" into a "verifiable facts layer" that supports the entire on-chain economy, and prediction markets serve as a magnifying glass to observe the competition in this red ocean.

a16z's key bet: Kalshi's weekly trading volume approaches $3 billion, transitioning from "prediction games" to financial infrastructure, the market begins to price "uncertainty."
The evolution of prediction markets: from niche products to "uncertainty pricing" infrastructure

Morning Report | Galaxy Digital announces Q1 2026 financial report; Liquid completes $18 million Series A financing; Polymarket plans to bring major exchanges to the U.S
Overview of Important Market Events on April 28

From a banned economist to the new CEO of Xinhua: Fu Peng has figured out the second half of traffic
This uproar in the crypto circle appears to be a cultural conflict between a traditional economist and a crypto OG, but looking deeper, it is merely the new fire leveraging Fu Peng's influence in the traditional financial sector to pry open a batch of client funds that were originally difficult to r...

Why Private Credit Became the First True Bridge from TradFi to DeFi
Unveiling the core logic of private credit leading RWA: it is no longer just simple tokenization, but rather a true reshaping of the practical value of asset on-chain through real returns and deep integration with the DeFi ecosystem.

Senior cryptocurrency investor: Blockchain is showing a siphoning effect on capital
Stablecoins are the first real-world assets on the blockchain, but they will not be the last. Every billion dollars in stablecoins generates $12.2 billion in economic activity and $19 million in protocol revenue annually; once capital is on the blockchain, it gains productivity and does not go back.

When traditional crypto derivatives start to subtract: Insights from Hyper Trade's products
Say goodbye to complex contracts, as crypto derivatives begin to "subtract": This article breaks down how Hyper Trade reduces hardcore risk pricing into "second-level multiple-choice questions," reshaping the trading experience for retail investors.

My view on blockchain has changed
In-depth Reflection on the Value of Blockchain Applications and the Time Dimension

Will AI Agents use bank cards? Why can't Agentic Payment avoid stablecoins and blockchain?
Why can't AI agents just swipe bank cards? An article to understand the new tiered payment system: stablecoins and blockchain are becoming the exclusive settlement language and verifiable trust foundation of the "machine economy" era.

Deconstructing 80 mainstream payment institutions and wallets worldwide
A comprehensive analysis of the global top 100 payment companies. Led by Alipay and WeChat, this article provides insights into the business logic and competitive advantages of over 80 top players.

The MiCA Fast Track for Cryptocurrency Licenses: Why OKX and BVNK Choose Malta
Countdown to the EU MiCA Licensing: Why do crypto giants like OKX choose Malta for their "first license"? A deep dive into the CASP license application process, business portfolio logic, and compliance pitfalls guide.

a16z Crypto: Stablecoins are rebuilding the global financial infrastructure
Stablecoins are evolving from cryptocurrency trading tools into a new infrastructure for global finance. They are not only changing cross-border payments but are also driving bank connectivity, corporate finance, foreign exchange liquidity, on-chain credit, and the globalization of the dollar into a...

ENI's RWA ambition: to create an enterprise-level BaaS platform that allows Web2 institutions to "go beyond just asset on-chain."
What are the differences between RWA 1.0 and RWA 2.0?

Morning Report | a16z releases global financial new stack report; Websea's withdrawal channel suspected of running away; Strategy purchased 3,273 bitcoins last week
Overview of Important Market Events on April 27

The most Crypto group of people is becoming the least Crypto
Hong Kong Carnival × Bangkok Money 20/20 Observation Notes

MSTR STRC In-depth Study: The BTC Financing Flywheel Behind the 11.5% Yield
STRC is a well-designed financing tool that transforms fixed income demand into buying pressure for Bitcoin.
Revisiting RWA: Nearly 50,000 people's first on-chain transaction was not Bitcoin, but stock indices and crude oil
The narrative of RWA is not about traditional finance trying to capture crypto users, but rather crypto trying to capture traditional users.
Altcoin Price Outlook 2026: The Rotation Is Coming — Just Not the Way You Think
Bitcoin dominance at 58%, Fear & Greed at 39. If you think altcoin season is dead, you're reading the wrong signals. Here's what the data actually says about what comes next.
Oracle: The Second Battlefield Behind the Prediction Market War
By 2026, the oracle track has essentially evolved from the early "data pipeline" into a "verifiable facts layer" that supports the entire on-chain economy, and prediction markets serve as a magnifying glass to observe the competition in this red ocean.
a16z's key bet: Kalshi's weekly trading volume approaches $3 billion, transitioning from "prediction games" to financial infrastructure, the market begins to price "uncertainty."
The evolution of prediction markets: from niche products to "uncertainty pricing" infrastructure
Morning Report | Galaxy Digital announces Q1 2026 financial report; Liquid completes $18 million Series A financing; Polymarket plans to bring major exchanges to the U.S
Overview of Important Market Events on April 28
From a banned economist to the new CEO of Xinhua: Fu Peng has figured out the second half of traffic
This uproar in the crypto circle appears to be a cultural conflict between a traditional economist and a crypto OG, but looking deeper, it is merely the new fire leveraging Fu Peng's influence in the traditional financial sector to pry open a batch of client funds that were originally difficult to r...
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com
