Curve Finance Hit by DNS Record Attack, Warns Users to Avoid Main Site
By: bitcoin ethereum news|2025/05/14 12:15:05
0
Share
In brief Curve Finance’s front-end website suffered a DNS compromise where attackers redirected users to a malicious site. The attack involved manipulating DNS records to point to a fraudulent site mimicking Curve’s interface with malicious scripts designed to trick users into approving token transfers. This isn’t Curve Finance’s first security incident. They experienced a similar DNS hijack in 2022 resulting in $570,000 in losses, and faced another exploit in 2023 involving Vyper programming vulnerabilities with estimated losses of $24 million. Decentralized protocol Curve Finance confirmed Tuesday that its front-end website was compromised, with attackers redirecting users to a fake site. “The DNS incident involving Curve Finance reflects a broader issue across the industry,” the project told Decrypt . “In recent weeks, there has been a noticeable increase in attacks targeting the infrastructure of various crypto projects.” The exploit redirected traffic to a malicious IP, the protocol said on social media. “User funds are safe. Curve smart contracts remain secure,” it added. The incident was first discovered on Monday afternoon, after which Curve Finance issued a preliminary response. While all smart contracts are safe, the domain name points to a malicious site which can drain your wallet! We are investigating and working on recovering the access. No sign of a compromise on our side https://t.co/YUmwtwt5PH — Curve Finance (@CurveFinance) May 12, 2025 Curve Finance later said the breach was “strictly limited to the DNS layer” and did not compromise its core infrastructure. Its security team promptly isolated the issue, initiated an investigation, and engaged with their domain registrar and security partners to address the situation, the project said. Security measures were in place “long before the incident,” the protocol added. What happened? According to Curve Finance, attackers manipulated the DNS records to point to an IP address under their control. A DNS record connects a domain name to details like an IP address, helping direct internet traffic. The fraudulent site, which mirrored Curve’s interface, reportedly contained malicious scripts aimed at tricking users into approving token transfers to the attackers. “DNS exploits are a form of social engineering at the infrastructure level. Attackers compromise the domain name system,” Meir Dolev, co-founder and CTO of blockchain security firm Cyvers, told Decrypt . If a site’s mapping changes due to stolen credentials or a registrar’s vulnerability, users may be redirected to harmful servers without realizing it. “These cloned sites can prompt users to connect wallets and approve transactions that drain funds,” Dolev explained. “It’s particularly dangerous because the average user can’t easily tell the difference—they still see the correct URL.” The attack doesn’t breach the protocol’s blockchain, but rather “exploits the trust layer” between the user and a decentralized app’s interface. “So long as users interact with Curve directly via verified contract addresses, their funds are likely unaffected,” Dolev noted. Hacking history This isn’t the first time Curve has been hit. Back in 2022, Curve Finance suffered a DNS hijack where attackers redirected users from its legitimate domain to a malicious site, resulting in approximately $570,000 in losses. Following the attack, Curve advised users to revoke any suspicious approvals and proposed migrating to the Ethereum Name Service (ENS) to mitigate future vulnerabilities. A year later, Curve Finance faced another exploit involving some Vyper programming language versions and the CRV/ETH pool. The loss across affected DeFi projects was estimated at $24 million at the time. Edited by Stacy Elliott. Daily Debrief Newsletter Start every day with the top news stories right now, plus original features, a podcast, videos and more. Source: https://decrypt.co/319414/curve-finance-dns-record-attack
You may also like

From Cash to Cryptocurrency: Moving Towards a Unified Regulatory Path for Illegal Payments
By establishing a framework based on the principle of "general law" and broadly defining the function of "payment tools," future innovations can be automatically included in the regulatory perspective, thereby breaking the passive cycle of "innovation-regulation-re-innovation-re-regulation" and guid...

Who will own the most Bitcoin in 2026
In this article, we will examine some individuals, companies, and wallets that have become crypto whales based on on-chain data and their own public statements, and investigate the amount of Bitcoin they hold.

A private feud lasting 10 years, if not for OpenAI's "hypocrisy," would not have led to the world's strongest AI company, Anthropic
What shapes the global AI landscape is not only the competition of technological routes but also a personal trauma that has never healed.

"Crypto Tsar" steps down: 130 days of political performance come to an end, how much of Trump's crypto promise remains?
The encryption czar has left, and Trump has muted.

From Utopian Narratives to Financial Infrastructure: The "Disenchantment" and Shift of Crypto VC
Financial infrastructure is the real reason that attracts venture capital investment in the cryptocurrency field.

A decade-long personal feud, if not for OpenAI's "hypocrisy," there would be no globally leading AI company Anthropic
Shaping the global AI landscape is not just a battle of technical paths, but also a wound of private trauma that has never healed

a16z: The True Meaning of Strong Chain Quality, Block Space Should Not Be Monopolized
Essentially, this attribute allows stakeholders to have a "virtual lane" within a high-throughput blockchain to ensure their transactions can be included.

a16z: The True Meaning of Strong Chain Quality, Block Space Should Not Be Monopolized
Essentially, this attribute allows stakeholders to have "virtual lanes" within a high-throughput blockchain, ensuring that their transactions can be included.

2% user contribution, 90% trading volume: The real picture of Polymarket
Is Polymarket a battleground for retail investors or an arena for institutions?

Trump Can't Take It Anymore, 5 Signals of the US-Iran Ceasefire
From Oil Prices and Elections to Secret Negotiations, Are the US and Iran Really Heading for a Ceasefire?

Judge Halts Pentagon's Retaliation Against Anthropic | Rewire News Evening Brief
The "Orwellian" Term Stymies Pentagon's Supply Chain Risk Label for Anthropic

Midfield Battle of Perp DEX: The Decliners, The Self-Savers, and The Latecomers
Hyperliquid has captured this wave of geopolitical market trends with commodity contracts. Decentralized exchanges are moving from internal competition within the crypto industry to a genuine alternative to traditional financial infrastructure, and this direction has only just begun.

Iran War Stalemate: What Signal Should the Market Follow?
Watch the Bond Market

Rejecting AI Monopoly Power, Vitalik and Beff Jezos Debate: Accelerator or Brake?
Can technological advancement be guided, or has it already gone beyond our control?

Insider Trading Alert! Will Trump Call a Truce by End of April?
Multiple Accounts Accurately Predict War, Earn $1.8 Million

After establishing itself as the top tokenized stock, does Ondo have any new highlights?
The total market capitalization of the global stock market is about $150 trillion, while the tokenized stocks market is currently only $10 billion in size, making it akin to a nascent super market that has just cracked the door open.

BIT Brand Upgrade First Appearance, Hosts "Trust in Digital Finance" Industry Event in Singapore
Discussing topics such as governance standards, compliance frameworks, and operational infrastructure within the context of the institutionalization process

OpenClaw Founder Interview: Why the US Should Learn from China on AI Implementation
In the US, using OpenClaw may get you fired; in China, not using it may get you fired
From Cash to Cryptocurrency: Moving Towards a Unified Regulatory Path for Illegal Payments
By establishing a framework based on the principle of "general law" and broadly defining the function of "payment tools," future innovations can be automatically included in the regulatory perspective, thereby breaking the passive cycle of "innovation-regulation-re-innovation-re-regulation" and guid...
Who will own the most Bitcoin in 2026
In this article, we will examine some individuals, companies, and wallets that have become crypto whales based on on-chain data and their own public statements, and investigate the amount of Bitcoin they hold.
A private feud lasting 10 years, if not for OpenAI's "hypocrisy," would not have led to the world's strongest AI company, Anthropic
What shapes the global AI landscape is not only the competition of technological routes but also a personal trauma that has never healed.
"Crypto Tsar" steps down: 130 days of political performance come to an end, how much of Trump's crypto promise remains?
The encryption czar has left, and Trump has muted.
From Utopian Narratives to Financial Infrastructure: The "Disenchantment" and Shift of Crypto VC
Financial infrastructure is the real reason that attracts venture capital investment in the cryptocurrency field.
A decade-long personal feud, if not for OpenAI's "hypocrisy," there would be no globally leading AI company Anthropic
Shaping the global AI landscape is not just a battle of technical paths, but also a wound of private trauma that has never healed
