Fun

Crypto execs on DeFi domain hacks: Don’t interact with crypto for now

News Feed - 2024-07-12 05:07:20

Ezra Reguerra46 minutes agoCrypto execs on DeFi domain hacks: Don’t interact with crypto for nowCoinGecko founder Bobby Ong explained that after Google sold its domain business to Squarespace, two-factor authentication was removed due to the forced migration of domains.312 Total views5 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksAs the vulnerability on Squarespace domains threatens the decentralized finance (DeFi) space with phishing attacks, Web3 professionals shared their advice on what users and those affected can do to avoid the attacks. 


On July 11, security investigator ZachXBT shared a Telegram post warning the community to stay away from the Compound Finance website, which redirected to a phishing site. The DeFi protocol was the first to be hijacked because of the vulnerability.


Following this, the Celer Network announced that it had also been attacked but successfully thwarted the attempt.


Meanwhile, DefiLlama developer “0xngmi” shared a list of domains vulnerable to the same attack vector. The list had over 100 protocols, including Polymarket, dYdX and Pendle Finance.Don’t interact with crypto for the next few days


CoinGecko founder Bobby Ong said the attack stemmed from Squarespace’s domain registrar. The executive explained that after Google sold its domain business to Squarespace, two-factor authentication (2FA) was removed due to the forced migration of domains.


This made the domains vulnerable. According to Ong, the community should wait until the issue is fixed before interacting with crypto again. “Best thing to do is to not interact with crypto and rest for the next couple of days until everything is resolved,” Ong added.


Related:CoinStats exploiter moves almost $1M to Tornado CashConsider transferring to other domain providers


Security researcher Samzsun said those affected by the recent domain hijacking on Squarespace might need to consider transferring to other providers. The white hat hacker recommended Cloudflare, Amazon Web Services Route 53, MarkMonitor and CSC DBS.


Meanwhile, Matthew Gould, the founder and CEO of Web3 domain provider Unstoppable Domains (UD), took the opportunity to explain how this type of attack may be avoided with Web3 domains. Gould explained:“By creating verified onchain records for domains we can offer an extra layer of protection browsers and others can check to help fight these types of attacks.”


The executive added that users could even configure their DNS records to not update unless they provide a verified onchain signature.


The executive also floated the idea of disallowing records updates without signatures from wallets. This would require hackers to attack the registrar and the user separately.


“So if your UD account was compromised, or UD itself as a registrar was compromised, but not your wallet, the malicious user could not alter your domain in DNS," Gould added.


Magazine:Lazarus Group’s favorite exploit revealed — Crypto hacks analysis# Blockchain# Security# Hackers# Cybersecurity# Hacks# DeFiAdd reaction

News Feed

The Genesis of BCH Tokenization: Over 10,000 SLP Tokens Built on Bitcoin Cash
The Genesis of BCH Tokenization: Over 10,000 SLP Tokens Built on Bitcoin CashThis week Bitcoin Cash fans have been discussing the milestone of over 10,000 Simple Ledger Protocol (SL
Report: Elon Musk’s Payments Vision for Twitter Takes Shape, Small Team Tasked to Build Infrastructure
Report: Elon Musk"s Payments Vision for Twitter Takes Shape, Small Team Tasked to Build Infrastructure Seven months ago, current Twitter owner Elon Musk said, prior to acquiring th
Vanuatu expects to pass long-awaited crypto bill in September
Felix Ng2 hours agoVanuatu expects to pass long-awaited crypto bill in SeptemberA Vanuatu policy consultant tells Cointelegraph the bill had been ready for a few years but had been delayed due to several cabinet changes.
Brayden Lindrea3 hours agoUS ‘the only country’s crypto startups should avoid, says Ripple CEOBrad Garlinghouse says Singapore, the U.K., the UAE and Switzerland are jurisdictions with “smart” crypto policies tha
Rakesh Upadhyay12 hours agoPrice analysis 6/26: SPX, DXY, BTC, ETH, BNB, XRP, ADA, DOGE, SOL, LTCAn onslaught of Bitcoin ETF applications could help BTC price find long-lasting support at the $30,000 level.2952 Total vie
Helen Partz12 hours agoGrayscale Bitcoin Trust among ARK’s top ETF performers in Q2 2023GBTC’s share in total ARKW’s holdings accounted for around 7.5%, roughly the same amount as Tesla, in Q2 2023, while Coinbase
Coindesk Up for Sale? Investors Circle Crypto News Publication Amidst Genesis Bankruptcy
Coindesk Up for Sale? Investors Circle Crypto News Publication Amidst Genesis Bankruptcy According to various reports, investors are reportedly interested in purchasing Coindesk, a
Nansen partners with Aptos for dashboard after chain users 2x in 6 months
Zoltan Vardai9 hours agoNansen partners with Aptos for dashboard after chain users 2x in 6 monthsAptos is among the firms aiming to ease Web3 onboarding, along with industry giants like Coinbase and MetaMask.652 Total vi
Tom Mitchelhill2 hours agoUS defense bill may be problematic for USDC and stablecoins: AnalystsA proposed U.S. national defense bill could subject stablecoins issuers to KYC and AML requirements they would be unable to c
Is Bitcoin Peak In? This Data Suggests Otherwise, Analytics Firm Says
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Human Rights Foundation’s Alex Gladstein Calls Bitcoin ‘An Escape Hatch From Tyranny’
Human Rights Foundation"s Alex Gladstein Calls Bitcoin "An Escape Hatch From Tyranny" The Human Rights Foundation (HRF)’s Alex Gladstein has heaped praise
Brandon Ginsberg11 hours agoHow agencies can play a role in NFT and digital collectable creationNo matter their specialization, agencies have a unique power to shape the trajectory of Web3 adoption and elevate the realm