Fun

Crypto execs on DeFi domain hacks: Don’t interact with crypto for now

News Feed - 2024-07-12 05:07:20

Ezra Reguerra46 minutes agoCrypto execs on DeFi domain hacks: Don’t interact with crypto for nowCoinGecko founder Bobby Ong explained that after Google sold its domain business to Squarespace, two-factor authentication was removed due to the forced migration of domains.312 Total views5 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksAs the vulnerability on Squarespace domains threatens the decentralized finance (DeFi) space with phishing attacks, Web3 professionals shared their advice on what users and those affected can do to avoid the attacks. 


On July 11, security investigator ZachXBT shared a Telegram post warning the community to stay away from the Compound Finance website, which redirected to a phishing site. The DeFi protocol was the first to be hijacked because of the vulnerability.


Following this, the Celer Network announced that it had also been attacked but successfully thwarted the attempt.


Meanwhile, DefiLlama developer “0xngmi” shared a list of domains vulnerable to the same attack vector. The list had over 100 protocols, including Polymarket, dYdX and Pendle Finance.Don’t interact with crypto for the next few days


CoinGecko founder Bobby Ong said the attack stemmed from Squarespace’s domain registrar. The executive explained that after Google sold its domain business to Squarespace, two-factor authentication (2FA) was removed due to the forced migration of domains.


This made the domains vulnerable. According to Ong, the community should wait until the issue is fixed before interacting with crypto again. “Best thing to do is to not interact with crypto and rest for the next couple of days until everything is resolved,” Ong added.


Related:CoinStats exploiter moves almost $1M to Tornado CashConsider transferring to other domain providers


Security researcher Samzsun said those affected by the recent domain hijacking on Squarespace might need to consider transferring to other providers. The white hat hacker recommended Cloudflare, Amazon Web Services Route 53, MarkMonitor and CSC DBS.


Meanwhile, Matthew Gould, the founder and CEO of Web3 domain provider Unstoppable Domains (UD), took the opportunity to explain how this type of attack may be avoided with Web3 domains. Gould explained:“By creating verified onchain records for domains we can offer an extra layer of protection browsers and others can check to help fight these types of attacks.”


The executive added that users could even configure their DNS records to not update unless they provide a verified onchain signature.


The executive also floated the idea of disallowing records updates without signatures from wallets. This would require hackers to attack the registrar and the user separately.


“So if your UD account was compromised, or UD itself as a registrar was compromised, but not your wallet, the malicious user could not alter your domain in DNS," Gould added.


Magazine:Lazarus Group’s favorite exploit revealed — Crypto hacks analysis# Blockchain# Security# Hackers# Cybersecurity# Hacks# DeFiAdd reaction

News Feed

Guggenheim Investment Fund to Invest $497 Million in Grayscale’s GBTC Seeking Bitcoin Exposure
Guggenheim Investment Fund to Invest $497 Million in Grayscale"s GBTC Seeking Bitcoin Exposure Guggenheim’s billion-dollar Marco Opportunities Fund (MOF) m
William Suberg21 minutes agoBitcoin Bollinger Bands hit key zone as BTC price fights for $27KBTC price is at a decision point within the context of the Bollinger Bands, but only time will tell whether Bitcoin can muster
Technical Analysis: AMP Surges, IOTX Lower After Friday’s Jump
Technical Analysis: AMP Surges, IOTX Lower After Friday"s Jump Friday’s big gainer IOTX fell lower on Saturday, as a red wave continued to submerge crypto markets to start t
Jesse Coghlan21 hours agoFTX alleges former exec used ‘hush money’ to silence whistleblowersThe lawsuit claims that former compliance officer Daniel Friedberg paid whistleblowers to stop them from exposing the “tru
$333 Million in Bitcoin Vanished from FTX Days Before the Company Filed for Bankruptcy Protection
$333 Million in Bitcoin Vanished from FTX Days Before the Company Filed for Bankruptcy Protection While it’s widely reported that hundreds of millions of dollars in Ethereum
Value Locked in Defi Loses $5.7 Billion in 5 Days, Smart Contract Tokens Shed 7.8% in 24 Hours
Value Locked in Defi Loses $5.7 Billion in 5 Days, Smart Contract Tokens Shed 7.8% in 24 Hours The total value locked (TVL) in decentralized finance (defi) has slid 8.53% over the
Tuttle Capital Files For 10 Leveraged Crypto ETFs Including TRUMP And Cardano
Tuttle Capital Management (TCM) has filed for ten different leveraged crypto ETFs in the United States, signaling an increasing interest from asset managers in leveraging cryptocurrencies and memecoins as viable investme
Mastercard Study: African Fintech Sector Had One of the Highest Year-on-Year Growth Rates in Funding in 2021
Mastercard Study: African Fintech Sector Had One of the Highest Year-on-Year Growth Rates in Funding in 2021 In 2021, African fintech startups accounted for 61% of the $2.7 billion
Amaka Nwaokocha10 hours agoOpenAI halts new ChatGPT Plus sign-ups amid high demandAccording to the company’s CEO, new sign-ups have been paused because the platform has exceeded its capacity, affecting users’ quality
Crypto-related investment fraud rose 53% in 2023: FBI
Ciaran Lyons4 hours agoCrypto-related investment fraud rose 53% in 2023: FBIAccording to the FBI, cryptocurrency-related investment fraud accounted for 86% of all investment losses within the United States in 2023.1863 T
Sharktron Defi Project Devs Exit Scam: Tron Foundation Says Part of Missing Funds Now Frozen
Sharktron Defi Project Devs Exit Scam: Tron Foundation Says Part of Missing Funds Now Frozen Developers of the Sharktron defi project have exit scammed with repo
Helen Partz44 minutes agoBinance fully exits Russia with sale to CommEXThe financial details of the deal remain undisclosed. However, as a full exit from Russia, Binance will have no ongoing revenue split, nor any option