Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Ethereum Updates: Centralized DNS Compromise Highlights DeFi Weaknesses as Aerodrome Suffers $1 Million Loss

Ethereum Updates: Centralized DNS Compromise Highlights DeFi Weaknesses as Aerodrome Suffers $1 Million Loss

Bitget-RWA2025/11/23 07:08
By:Bitget-RWA

- Aerodrome Finance suffered a DNS hijacking attack on Nov 22, 2025, redirecting users to phishing sites that siphoned over $1M in assets through deceptive transaction approvals. - Attackers exploited vulnerabilities in centralized domain registrar Box Domains, forcing users to approve unlimited access to NFTs and stablecoins via two-stage signature requests. - The protocol shut down compromised domains, urged ENS-based access, and revoked recent token approvals, marking its second major front-end breach i

Aerodrome Finance, the top decentralized exchange (DEX) on Coinbase's Base network, is currently probing a possible DNS hijacking incident that affected its centralized web domains, leading to urgent advisories for users to steer clear of its main sites. The event, which took place on November 22, 2025, saw attackers redirecting visitors to fraudulent websites intended to deceive them into authorizing harmful transactions,

and . The team stressed that all smart contracts are still safe, but users were instructed to access the platform through decentralized (ENS) mirrors .

The exploit targeted weaknesses in Aerodrome's centralized domain registrar, Box Domains, enabling cybercriminals to seize control of the .finance and .box domains. Some users reported facing misleading interfaces that

asking for unrestricted access to assets like NFTs, ETH, and . One affected individual described a two-step attack where an apparently harmless signature request was quickly succeeded by multiple approval prompts, the permissions. Initial assessments indicate that over $1 million was stolen from compromised wallets within an hour, although .

In response, Aerodrome disabled access to the compromised domains and

and aero.drome.eth.link. The team also via tools like Revoke.cash to reduce exposure. This is the second significant front-end compromise for Aerodrome in 2025, that led to more than $300,000 in user losses. The attack happened shortly after Aerodrome revealed its merger with Velodrome, a rival DEX on , to create a cross-chain ecosystem named "Aero". Despite the incident, the value of the AERO token held steady, over the past day.

This event underscores persistent security issues in DeFi, where vulnerabilities in front-end systems—unlike on-chain smart contract attacks—can be exploited without compromising the protocol’s core infrastructure.

the project's actions, highlighting that ENS-based domains and DNS infrastructure managed by multisig wallets were unaffected, and that leading security experts are involved in the investigation. Meanwhile, of depending on centralized DNS services, a widespread practice in DeFi despite the industry’s focus on decentralization.

Ethereum Updates: Centralized DNS Compromise Highlights DeFi Weaknesses as Aerodrome Suffers $1 Million Loss image 0

The Aerodrome team is

to fix the problem and has appealed for immediate assistance to address the security gap. crypto theft losses, with October 2025 seeing the lowest monthly total of the year at $18.18 million—a sharp decrease from September’s $127 million. Nonetheless, experts caution that attackers are becoming more advanced, that complicate defense efforts.

As the inquiry proceeds,

that liquidity pools and protocol reserves are unaffected, and they urge users to remain cautious and avoid suspicious domains until further notice.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Bitcoin News Today: Bitcoin's Unstable Holiday Periods Hide Average Gains of 6%

- Bitcoin's Thanksgiving-to-Christmas performance shows equal odds of rising or falling, with a 6% average seasonal return despite volatility. - Historical extremes include a 50% 2020 rally and 2022's 3.62% drop post-FTX collapse, amid a $2.49-to-$91,600 long-term surge since 2011. - 2025's $91,600 price reflects ongoing recovery from 2024's $95,531 peak, with institutional crypto adoption and macroeconomic factors shaping future trajectories. - Analysts advise dollar-cost averaging for retail investors, w

Bitget-RWA2025/11/27 13:56
Bitcoin News Today: Bitcoin's Unstable Holiday Periods Hide Average Gains of 6%

Australia Strikes a Balance Between Fostering Crypto Innovation and Safeguarding Investors with Updated Regulations

- Australia introduces 2025 Digital Assets Framework Bill to regulate crypto platforms under ASIC, creating "digital asset platform" and "tokenized custody platform" licenses. - The framework mandates custody standards, transparency requirements, and lighter regulations for small operators (<$5k per customer) to balance innovation with investor protection. - Global alignment with UAE and EU crypto regulations is emphasized, while addressing risks from past failures like FTX through stricter enforcement and

Bitget-RWA2025/11/27 13:56
Australia Strikes a Balance Between Fostering Crypto Innovation and Safeguarding Investors with Updated Regulations

PENGU Token's Latest Price Fluctuations and Blockchain Indicators: An Analytical Perspective on Technical Factors and Institutional Activity

- PENGU token's recent volatility and on-chain activity spark debate over institutional involvement in the crypto market. - Technical indicators show conflicting signals: overbought RSI vs. positive MACD/OBV momentum since November 2025. - Whale accumulation and Solana integration suggest strategic buying, while team wallet outflows highlight market uncertainty. - Social media sentiment drives short-term price swings, but structural risks like tokenomics and regulatory ambiguity persist. - Institutional ad

Bitget-RWA2025/11/27 13:56
PENGU Token's Latest Price Fluctuations and Blockchain Indicators: An Analytical Perspective on Technical Factors and Institutional Activity

GameStop's Profit Strategy: Short Sellers, Brick-and-Mortar Stores, and Interest Rate Expectations Intersect

- GameStop (GME) shares rose near 52-week lows amid high short interest and retail-driven speculation, with a potential short squeeze looming as open options activity surged. - Institutional investors cut $5.4B in MicroStrategy (MSTR) holdings, linking crypto-focused MSTR to GME's 2021 meme stock dynamics amid MSCI index exclusion risks. - A December Fed rate cut (85% probability) could boost retail spending and speculative appetite, countering bearish positioning despite GME's 21.8% Q3 revenue growth. - A

Bitget-RWA2025/11/27 13:18
GameStop's Profit Strategy: Short Sellers, Brick-and-Mortar Stores, and Interest Rate Expectations Intersect