CryptoMediaClub
Friday, December 19, 2025
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis
  • en English
    • ar العربية
    • zh-CN 简体中文
    • cs Čeština‎
    • nl Nederlands
    • en English
    • et Eesti
    • fr Français
    • de Deutsch
    • iw עִבְרִית
    • it Italiano
    • ja 日本語
    • ko 한국어
    • lv Latviešu valoda
    • pl Polski
    • pt Português
    • ru Русский
    • sk Slovenčina
    • es Español
    • sv Svenska
    • uk Українська
No Result
View All Result
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis
  • en English
    • ar العربية
    • zh-CN 简体中文
    • cs Čeština‎
    • nl Nederlands
    • en English
    • et Eesti
    • fr Français
    • de Deutsch
    • iw עִבְרִית
    • it Italiano
    • ja 日本語
    • ko 한국어
    • lv Latviešu valoda
    • pl Polski
    • pt Português
    • ru Русский
    • sk Slovenčina
    • es Español
    • sv Svenska
    • uk Українська
No Result
View All Result
CryptoMediaClub
No Result
View All Result
Home All news

Base’s Top DEX Aerodrome Hit by a Suspected Frontend Security Breach

22.11.2025
A A
0
118
VIEWS
ShareShare

Aerodrome Finance, the leading decentralized exchange on the Base network, confirmed it is investigating a suspected DNS hijacking attack that compromised its centralized domains.

The protocol warned users to avoid accessing its primary .finance and .box domains and instead use two secure decentralized mirrors hosted on ENS infrastructure.

The attack unfolded rapidly, with affected users reporting malicious signature requests designed to drain multiple assets, including NFTs, ETH, and USDC, through unlimited approval prompts.

While the team maintains that all smart contracts remain secure, the frontend compromise exposed users to sophisticated phishing attempts that could have drained wallets for those who weren’t carefully monitoring transaction approvals.

We’re actively investigating a frontend compromise.
Please do not access the site through any URL — primary domain or decentralized mirrors — until we confirm everything is safe.
All smart contracts appear secure. Updates soon.

— Aerodrome (@AerodromeFi) November 22, 2025

DNS Hijacking Forces Emergency Protocol Lockdown

Aerodrome’s investigation began when the team detected unusual activity on its primary domain infrastructure approximately six hours before issuing public warnings.

The protocol immediately flagged its domain provider, Box Domains, as potentially compromised and urged the service to reach out urgently.

Within hours, the team confirmed that both centralized domains, .finance and .box, had been hijacked and remained under attacker control.

The protocol responded by shutting down access to all primary URLs while establishing two verified safe alternatives: aero.drome.eth.limo and aero.drome.eth.link.

Update: centralized domains (.finance and .box) remain compromised. Please do not use either domain for now.
Two decentralized mirrors remain safe to use:https://t.co/7U8yRQs1Lihttps://t.co/mnbqM27GdS
All smart contracts remain secure.
We’ll provide further updates as the… https://t.co/1VPGDnq10L

— Aerodrome (@AerodromeFi) November 22, 2025

These decentralized mirrors leverage the Ethereum Name Service, which operates independently of traditional DNS systems that are vulnerable to hijacking.

The team emphasized that smart contract security remained intact throughout the incident, containing the breach exclusively to frontend access points.

Sister protocol Velodrome faced similar threats, prompting its team to issue parallel warnings about domain security.

The coordinated nature of the warnings suggested that attackers may have systematically targeted Box Domains’ infrastructure to compromise multiple DeFi platforms simultaneously.

Users Report Aggressive Multi-Asset Drain Attempts

One affected user described encountering the malicious interface before official warnings circulated, detailing how the compromised site deployed a deceptive two-stage attack.

The hijacked frontend first requested what appeared to be a harmless signature containing only the number “1,” establishing initial wallet connection.

Immediately after this seemingly innocuous request, the interface triggered an unlimited number of approval prompts for NFTs, ETH, USDC, and WETH.

“It asked for a simple signature, then instantly tried unlimited approvals to drain NFTs, ETH, and USDC,” the user reported. “If you weren’t paying attention, you could’ve lost everything.”

The victim documented the attack through screenshots and video recordings, capturing the progression from initial signature request through multiple drain attempts.

Before these unlimited approval prompts, the hijacked site first asked me to sign a harmless-looking message with just “1”.
Right after, it triggered approvals to drain NFTs, ETH, USDC, WETH, everything.
If you weren’t paying attention, you could lose your whole wallet instantly. pic.twitter.com/bJxFazMEvn

— Mynimal Monster (@MynimalM) November 22, 2025

Their investigation, conducted with AI assistance, examined browser configurations, extensions, DNS settings, and RPC endpoints before concluding that the attack pattern aligned with DNS hijacking methodology.

Another community member shared an experience with a separate, draining incident recently, describing themselves as a seasoned veteran and full-stack developer who still fell victim to sophisticated attacks.

Despite technical expertise, the user lost significant funds and spent 3 days developing a Jito bundle-based script to recover roughly 10-15% of the stolen assets through on-chain stealth operations.

October Records Lowest Crypto Hack Losses of the Year

The Aerodrome incident emerged during October’s unexpected security milestone, as the crypto market experienced its lowest monthly hack losses of the year.

Data from blockchain security firm PeckShield shows only $18.18 million was stolen across 15 separate incidents, representing a steep 85.7% decline from September’s $127.06 million.

Without the late-month Garden Finance exploit, total losses would have hovered near $7.18 million, the lowest single-month value since early 2023.

The largest incidents occurred at Garden Finance, Typus Finance, and Abracadabra, which collectively accounted for $16.2 million of total stolen funds.

🚨 Garden Finance loses $10.8 million in exploit as on-chain data shows over 25% of platform volume linked to stolen funds from major security breaches.#Crypto #Bitcoin #Exploithttps://t.co/Tb8zYW8oPH

— Cryptonews.com (@cryptonews) October 30, 2025

Garden Finance, a Bitcoin peer-to-peer protocol, disclosed on October 30 that it had been exploited for more than $10 million after one of its solvers was compromised, with the breach affecting only the solver’s own inventory.

Typus Finance suffered an oracle manipulation attack on October 15 that drained roughly $3.4 million from its liquidity pools, traced to a flaw in one of its TLP contracts that caused the project’s native token to drop about 35%.

DeFi lending platform Abracadabra endured its third exploit since launch around the same time, resulting in roughly $1.8 million in MIM stablecoin losses after hackers bypassed solvency checks through a smart contract vulnerability.

The post Base’s Top DEX Aerodrome Hit by a Suspected Frontend Security Breach appeared first on Cryptonews.

Share9Tweet6ShareSharePin2

Related Posts

Crypto.com Introduces New Referral Program With More Rewards and Real-Time Dashboard
All news

Crypto.com Introduces New Referral Program With More Rewards and Real-Time Dashboard

19.12.2025
0

In Crypto.com’s latest product update, the leading crypto exchange app released an upgraded version of its referral program, offering up...

Read moreDetails
Senate Confirms Pro-Crypto Mike Selig as CFTC Chair — What To Expect

Senate Confirms Pro-Crypto Mike Selig as CFTC Chair — What To Expect

19.12.2025
Aptos Proposes Quantum-Resistant Signatures to Future-Proof Blockchain Security

Aptos Proposes Quantum-Resistant Signatures to Future-Proof Blockchain Security

19.12.2025
IcomTech Promoter Sentenced to Nearly Six Years in Prison Over Crypto Ponzi Scheme

IcomTech Promoter Sentenced to Nearly Six Years in Prison Over Crypto Ponzi Scheme

19.12.2025
Terraform Liquidators Allege Jump Trading Helped Fuel Crypto’s Biggest Crash: Report

Terraform Liquidators Allege Jump Trading Helped Fuel Crypto’s Biggest Crash: Report

19.12.2025
Load More
Next Post
Can MicroStrategy survive reclassification as a Bitcoin investment vehicle?

Can MicroStrategy survive reclassification as a Bitcoin investment vehicle?

0 0 votes
Рейтинг статьи
Subscribe
Notify of
guest
guest
0 комментариев
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Recommended

XRP Price Prediction: Swiss Bank Embraces Ripple’s RLUSD – Billions Flowing into XRP?

XRP Price Prediction: Swiss Bank Embraces Ripple’s RLUSD – Billions Flowing into XRP?

6 months ago
Ripple Vows to Defend Against SEC Lawsuit, Significantly Impacting the Crypto Landscape

Ripple Vows to Defend Against SEC Lawsuit, Significantly Impacting the Crypto Landscape

2 years ago
The Fed has little ammo left as $30K Bitcoin price becomes key battle-line

The Fed has little ammo left as $30K Bitcoin price becomes key battle-line

3 years ago
Kakaopay Stock Plunges 17% as Korean Exchange Suspends Trading Over Stablecoin Exposure

Kakaopay Stock Plunges 17% as Korean Exchange Suspends Trading Over Stablecoin Exposure

6 months ago

Categories

  • All news
  • Altcoins
  • Analysis
  • Bitcoin
  • Blockchain
  • Ethereum
  • NFT
No Result
View All Result

Highlights

Aptos Proposes Quantum-Resistant Signatures to Future-Proof Blockchain Security

IcomTech Promoter Sentenced to Nearly Six Years in Prison Over Crypto Ponzi Scheme

Terraform Liquidators Allege Jump Trading Helped Fuel Crypto’s Biggest Crash: Report

Asia Market Open: Bitcoin Slides As Asian Markets Take Cues From Tech Recovery

‘Severe Mistake’: Lawmakers May Limit De Minimis Tax Exemption to Stablecoins Only

Cardano’s new roadmap assumes a 500% price explosion to mask an alarming gap in real protocol revenue

Trending

Crypto.com Introduces New Referral Program With More Rewards and Real-Time Dashboard
All news

Crypto.com Introduces New Referral Program With More Rewards and Real-Time Dashboard

19.12.2025
0

In Crypto.com’s latest product update, the leading crypto exchange app released an upgraded version of its referral...

Bitcoin encryption isn’t at risk from quantum computers for one simple reason: it doesn’t actually exist

Bitcoin encryption isn’t at risk from quantum computers for one simple reason: it doesn’t actually exist

19.12.2025
Senate Confirms Pro-Crypto Mike Selig as CFTC Chair — What To Expect

Senate Confirms Pro-Crypto Mike Selig as CFTC Chair — What To Expect

19.12.2025
Aptos Proposes Quantum-Resistant Signatures to Future-Proof Blockchain Security

Aptos Proposes Quantum-Resistant Signatures to Future-Proof Blockchain Security

19.12.2025
IcomTech Promoter Sentenced to Nearly Six Years in Prison Over Crypto Ponzi Scheme

IcomTech Promoter Sentenced to Nearly Six Years in Prison Over Crypto Ponzi Scheme

19.12.2025
  • All news
  • Altcoins
  • Bitcoin
  • Blockchain
  • Ethereum
  • NFT
  • Analysis
Editor: cryptomediaclub.com@gmail.com
Advertising: digestmediaholding@gmail.com

Disclaimer: Information found on CryptoMediaClub is those of writers quoted. It does not represent the opinions of CryptoMediaClub on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoMediaClub covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.

© 2023 Crypto News. All Rights Reserved

No Result
View All Result
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis

Disclaimer: Information found on CryptoMediaClub is those of writers quoted. It does not represent the opinions of CryptoMediaClub on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoMediaClub covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.

© 2023 Crypto News. All Rights Reserved

wpDiscuz