Fun

Ether.fi thwarts domain account takeover attempt, confirms user funds safe

News Feed - 2024-09-25 08:09:53

Josh O"Sullivan7 hours agoEther.fi thwarts domain account takeover attempt, confirms user funds safeEther.fi credits security upgrades and partners for thwarting a domain account takeover before user funds were compromised.1650 Total views3 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTCOINTELEGRAPH IN YOUR SOCIAL FEEDFollow ourSubscribe onEther.fi, a decentralized finance (DeFi) staking protocol, has reported that no user funds were compromised during the recent domain takeover attack.


On Sept. 24, the DeFi protocol faced an attempted domain account takeover involving their domain registrar, Gandi.net, but was stopped before significant harm could occur.


The Ether.fi internal team confirmed that attackers could not present a malicious decentralized application (DApp) on any Ether.fi-related domain.Source:Ether.fi


Related:Ether.fi launching ‘crypto-native’ credit card on ZK-rollup ScrollEther.fi responds to attack


The breach began on Sept. 24 when the DeFi protocol received a recovery notification email from Gandi.net at 4:38 pm UTC.


After verification through the protocol’s security measures, including “SPF, DKIM, and DMARC authentication records,” it was discovered that the attacker was behind the email.


According to an official Ether.fi summary Gitbook post, “it was established an attacker attempted to use the legitimate Gandi recovery flow to gain access to etherfi’s Gandi account.”


Ether.fi immediately contacted Gandi across multiple platforms, and by 7:30 pm UTC, the DeFi staking protocol had confirmed that its account had been locked down to prevent further tampering.


Related:Restaking is ‘inevitable,’ but the risks are still uncertain — Ether.fi CEOSecurity measures


The DeFi protocol implemented security upgrades before the attempted attack, which acted as a buffer to mitigate the threat of the domain takeover attempt.


According to the official Gitbook post weeks prior, Ether.fi noticed an increase in the exploitation of similar attack vectors across other platforms. 


As a precaution, the protocol upgrades its key platforms to require hardware authentication for account recovery and management procedures.


Ether.fi credited its security partners, including Seal911, Doppel, Ethena, and Distrust, for immediate assistance during the attack.


Related:Omni Network seals $600M deal with Ether.FiFollow-up communication and fund safety


On Sept. 24 at 07:13 pm UTC, Ether.fi communicated to its users via social media platform X that they should not “click on any links” or interact with their domain.


The DeFi protocol noted that official communications would come solely through X or Discord and explicitly stated that no communication would come through email.


After resolving the incident, the team stated that “all funds are safe” and that the attackers had “no opportunity” to issue any malicious DApps “on any ether.fi related domain.”


Magazine:Lady of Crypto will be ‘all out of crypto’ by September 2025: X Hall of Flame# Blockchain# Security# Decentralization# Ethereum# Hackers# Cybersecurity# Hacks# DeFiAdd reaction

News Feed

Chinese Stocks Tumble After Disastrous Industrial Production Data
Chinese industrial production showed renewed weakness in August. | Image: AFP / ChinaStocks in mainland China and Hong Kong tumbled on Monday after Beijing reported a sharper than e
Bitcoin’s Mining Difficulty Slides 5% Dropping to Levels Not Seen Since March
Bitcoin"s Mining Difficulty Slides 5% Dropping to Levels Not Seen Since March On July 21, 2022, at 2:14 p.m. (ET) at block height 745,920, Bitcoin’s mining difficulty droppe
Report: Nigerian Central Bank Targets Tenfold Increase in Number of CBDC Users, Governor Says Use of Cash Will ‘Dissipate to Zero’
Report: Nigerian Central Bank Targets Tenfold Increase in Number of CBDC Users, Governor Says Use of Cash Will "Dissipate to Zero" Despite the apparent slow embrace of the e-naira
Highly Anticipated Bitcoin Upgrade Taproot Activates — Taproot Script-Spends Seen in the Wild
Highly Anticipated Bitcoin Upgrade Taproot Activates — Taproot Script-Spends Seen in the Wild Bitcoin advocates are celebrating the successful implementation of the Taproot upgra
‘Bitcoin Is Not a Privacy Coin’ Says Crypto Evangelist Andreas Antonopoulos
"Bitcoin Is Not a Privacy Coin" Says Crypto Evangelist Andreas AntonopoulosAndreas Antonopoulos discussed how he desired to see Bitcoin have more “privacy features” in a
Central Bank of Venezuela Announces ‘Digital Bolivar’ Redenomination Plan
Central Bank of Venezuela Announces "Digital Bolivar" Redenomination Plan The Central Bank of Venezuela announced the new redenomination plan for its fiat curren
Bailouts From Asia to the EU Signal Recession and Potential Crypto Opportunity
Bailouts From Asia to the EU Signal Recession and Potential Crypto Opportunity China’s Hengfeng Bank is set to get a $14.2 billion bailout from both Chinese government and
Tether mints 1.3B USDT since market bottom — Can it push Bitcoin above $65K?
Zoltan Vardai11 hours agoTether mints 1.3B USDT since market bottom — Can it push Bitcoin above $65K?The newly minted stablecoins could help push Bitcoin’s price above the $65,000 resistance, which is the short-term
Robert Kiyosaki Says ‘We Are in Global Recession’ — Warns of Soaring Bankruptcies, Unemployment, Homelessness
Robert Kiyosaki Says "We Are in Global Recession" — Warns of Soaring Bankruptcies, Unemployment, Homelessness The famous author of the best-selling book Rich Dad Poor Dad, Robert
Gareth Jenkinson10 hours agoBitget releases MPC wallet, includes 2/3 private key shardingCryptocurrency exchange Bitget has released a multiparty computation wallet to improve asset security and user experience.9917 Tota
Biggest Movers: XRP Hits Fresh 5-Month High on Tuesday, Extending Recent Win Streak
Biggest Movers: XRP Hits Fresh 5-Month High on Tuesday, Extending Recent Win Streak Xrp rose to a fresh five-month high on Tuesday, as prices climbed for a fourth straight session
Helen Partz13 hours agoIdentity checks on crypto exchanges at risk as AI deepfakes evolveOnce HeyGen’s AI-generated digital avatar is available to the public, users will be able to create a video with a real life-like