Description

A recent security breach has exposed a critical vulnerability in DeFi (Decentralized Finance) apps hosted on Squarespace, a popular website-building platform. Hackers have hijacked the Domain Name System (DNS) records of these applications, potentially affecting over 120 DeFi protocols, including Compound and Celer Network. DNS functions as the internet's phonebook, translating domain names into IP addresses. On July 11, 2024, attackers compromised DNS records of DeFi apps, redirecting users to malicious sites. Oxngmi, a developer at DefiLlama, shared a list of potentially vulnerable domains registered with Squarespace. Blockaid's investigation revealed that the attacker took control of the DNS registry for Compound Finance and attempted to compromise Celer Network's registry. This allowed the attackers to redirect users to phishing sites to steal sensitive information and funds. The attack was discovered when users reported that Compound's interface redirected them to a malicious website. Celer Network also detected and thwarted an attempted domain takeover. Both platforms acknowledged the incidents in separate statements.further analysis indicated that the attackers specifically targeted Squarespace domains, putting all DeFi apps with such domains at risk. In response, MetaMask, a popular Web3 wallet, implemented a warning system to flag potentially compromised DeFi apps, adding an extra layer of security for users. While the exact methods used by the attackers remain under investigation, it is speculated that the attack vector originated from Google domain accounts used by these protocols. Squarespace's acquisition of 10 million domains from Google Domains in 2023 may have provided attackers with access to sensitive DNS information. these incidents underscore the need for DeFi developers to prioritize robust security measures and for users to exercise caution when interacting with DeFi apps.