CryptoMediaClub
Tuesday, October 14, 2025
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis
No Result
View All Result
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis
No Result
View All Result
CryptoMediaClub
No Result
View All Result
Home All news

dYdX Exchange Releases Postmortem on $31K Squarespace Account Hack Lost

26.07.2024
A A
0
122
VIEWS
ShareShare

dYdX, a prominent crypto exchange, announced on July 23 that its version 3.0 website had been compromised.

Users have been advised to avoid visiting the version 3.0 site or clicking any links until further notice. However, the team assured users that version 4.0 remains unaffected and is functioning normally.

dYdX has released a detailed postmortem on the Squarespace account hack, outlining the events and their responses. The exchange has decided to change domain registrars and continues to work with SEAL and other partners to prevent future incidents.

dYdX Exchange Website Compromised Due to Social Engineering Attack

The domain registrar for https://t.co/Ym1dFLMmm5 (previously Squarespace) has confirmed that on July 23rd, dYdX Trading’s Squarespace account was accessed by unauthorized individuals after they successfully social-engineered Squarespace customer support.

— dYdX (@dYdX) July 25, 2024

According to the postmortem, the breach occurred after unauthorized individuals accessed dYdX Trading’s Squarespace account through a social engineering attack on Squarespace customer support.

During the two-hour hijacking of the exchange domain, two users lost funds totaling approximately $31,000. dYdX Trading is in contact with the affected users to ensure they are compensated.

In 2023, Squarespace acquired all domains from the now-defunct Google Domains, migrating them over several months. The dydx.exchange domain, owned by dYdX Trading, was moved to Squarespace on June 15, 2024.

On July 9, attackers gained access to the dydx.exchange domain and modified the DNS nameservers from Cloudflare to DDoS-Guard.

This initial attack was mitigated by DNSSEC settings, which prevented users from accessing the compromised site. DYdX quickly resolved the issue through password and two-factor authentication (2FA) rotations.

Following reports of similar attacks on crypto-specific domains, SEAL, a crypto-focused security team, initiated an investigation. It was discovered that an OAuth vulnerability on Squarespace had been exploited, which Squarespace addressed and fixed on July 12.

Despite this, the dydx.exchange domain was compromised again on July 23. Attackers managed to change the DNS Nameservers and remove DNSSEC settings, hosting a malicious site that tricked users into transferring Ethereum and ERC20 tokens.

During this period, dYdX collaborated with SEAL and other partners to block malicious sites on popular crypto wallets like Metamask and Phantom. Despite these efforts, two users lost $31,000 during the attack.

dYdX Exchange Recovers Website Following Squarespace Account Hack

Please see the full post-mortem below.https://t.co/vHSGRZpzpx

— dYdX (@dYdX) July 25, 2024

The postmortem further revealed that the attacker had set the domain admin email to an address ending in outlook.com, with a username similar to the legal name of the billing administrator on dYdX’s account. This suggested a social engineering attack, as the attacker used a believable email address.

According to dYdX, its communications with Squarespace revealed that a human error initiated the takeover during the account-recovery process.

The attacker bypassed 2FA and modified the account email without providing valid security credentials. Squarespace’s customer service did not attempt to contact any other listed admins on the domain before making these changes.

In response to the attack, dYdX transferred its domain registration to Cloudflare to enhance security. The transfer was expedited and completed within six hours.

dYdX confirmed that there were no security issues with its smart contracts, backend systems, or the dYdX Chain as a result of the incidents.

https://t.co/Ym1dFLLOwx website has been recovered by dYdX Trading Inc. 🙏

Please note that your machine may still be caching the compromised site.

Make sure to clear your cache and restart your browser before connecting to the website.

— dYdX (@dYdX) July 23, 2024

The dYdX team stated social media X, advising users to clear their browser cache and restart their browser before reconnecting to the website to ensure they were not accessing the compromised site.

The post dYdX Exchange Releases Postmortem on $31K Squarespace Account Hack Lost appeared first on Cryptonews.

Share9Tweet6ShareSharePin2

Related Posts

Why Crypto Investors Are Adding Mutuum Finance (MUTM) Alongside Solana (SOL) in 2025 Portfolios
All news

Why Crypto Investors Are Adding Mutuum Finance (MUTM) Alongside Solana (SOL) in 2025 Portfolios

14.10.2025
0

As the 2025 bull run gathers pace, portfolio strategies are evolving. While established giants like Solana (SOL) continue to anchor...

Read moreDetails
Citibank to Launch Crypto Custody Services in 2026 After 3 Years of Preparation

Citibank to Launch Crypto Custody Services in 2026 After 3 Years of Preparation

14.10.2025
California Becomes First State to Protect Unclaimed Crypto from Forced Liquidation

California Becomes First State to Protect Unclaimed Crypto from Forced Liquidation

14.10.2025
[LIVE] Crypto News Today: Latest Updates for Oct. 14, 2025 – Crypto Market Turns Cautious After Rebound as Whales Load Up on Massive Shorts; GameFi Leads Sector Gains

[LIVE] Crypto News Today: Latest Updates for Oct. 14, 2025 – Crypto Market Turns Cautious After Rebound as Whales Load Up on Massive Shorts; GameFi Leads Sector Gains

14.10.2025
Congress Won’t Pass A Funding Bill Until November, Majority of Polymarket Bettors Say

Congress Won’t Pass A Funding Bill Until November, Majority of Polymarket Bettors Say

14.10.2025
Load More
Next Post
Republican Senator Roger Marshall Backs Out of Controversial Crypto Bill

Republican Senator Roger Marshall Backs Out of Controversial Crypto Bill

0 0 votes
Рейтинг статьи
Subscribe
Notify of
guest
guest
0 комментариев
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Recommended

China Imposes Criminal Penalties for Theft of Digital Collections

China Imposes Criminal Penalties for Theft of Digital Collections

2 years ago
[LIVE] Crypto News Today: Latest Updates for July 17, 2025 – Altcoin Mania is Here, ETH Crosses $3.3K, XRP Holds Above $3

[LIVE] Crypto News Today: Latest Updates for July 17, 2025 – Altcoin Mania is Here, ETH Crosses $3.3K, XRP Holds Above $3

3 months ago
Voyager Now Moves To Liquidation Plan After Failed Deals With Binance.US

Voyager Now Moves To Liquidation Plan After Failed Deals With Binance.US

2 years ago
Bitcoin’s “Head Fake”: A Ticking Time Bomb or a Return to Bullish Trends?

Bitcoin’s “Head Fake”: A Ticking Time Bomb or a Return to Bullish Trends?

2 years ago

Categories

  • All news
  • Altcoins
  • Analysis
  • Bitcoin
  • Blockchain
  • Ethereum
  • NFT
No Result
View All Result

Highlights

Citibank to Launch Crypto Custody Services in 2026 After 3 Years of Preparation

California Becomes First State to Protect Unclaimed Crypto from Forced Liquidation

[LIVE] Crypto News Today: Latest Updates for Oct. 14, 2025 – Crypto Market Turns Cautious After Rebound as Whales Load Up on Massive Shorts; GameFi Leads Sector Gains

Congress Won’t Pass A Funding Bill Until November, Majority of Polymarket Bettors Say

Crypto Price Prediction Today 13 October – XRP, Cardano, PENGU

Bitcoin Price Prediction: Trump, BlackRock, and Strategy Fuel Renewed Optimism as Bulls Target $122K

Trending

$2B Ethena USDe depeg exposes cracks in crypto’s ‘synthetic dollar’ system
Analysis

$2B Ethena USDe depeg exposes cracks in crypto’s ‘synthetic dollar’ system

14.10.2025
0

Ethena’s synthetic dollar, USDe, shed over $2 billion in market capitalization after briefly losing its dollar peg...

Why Crypto Investors Are Adding Mutuum Finance (MUTM) Alongside Solana (SOL) in 2025 Portfolios

Why Crypto Investors Are Adding Mutuum Finance (MUTM) Alongside Solana (SOL) in 2025 Portfolios

14.10.2025
Bitcoin falters again causing $200B wipeout: Will BTC hold $110k or break to $104k?

Bitcoin falters again causing $200B wipeout: Will BTC hold $110k or break to $104k?

14.10.2025
Citibank to Launch Crypto Custody Services in 2026 After 3 Years of Preparation

Citibank to Launch Crypto Custody Services in 2026 After 3 Years of Preparation

14.10.2025
California Becomes First State to Protect Unclaimed Crypto from Forced Liquidation

California Becomes First State to Protect Unclaimed Crypto from Forced Liquidation

14.10.2025
  • All news
  • Altcoins
  • Bitcoin
  • Blockchain
  • Ethereum
  • NFT
  • Analysis
Editor: cryptomediaclub.com@gmail.com
Advertising: digestmediaholding@gmail.com

Disclaimer: Information found on CryptoMediaClub is those of writers quoted. It does not represent the opinions of CryptoMediaClub on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoMediaClub covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.

© 2023 Crypto News. All Rights Reserved

No Result
View All Result
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis

Disclaimer: Information found on CryptoMediaClub is those of writers quoted. It does not represent the opinions of CryptoMediaClub on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoMediaClub covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.

© 2023 Crypto News. All Rights Reserved

wpDiscuz