Curve Finance front end UI compromised following DNS hack – users advised to exercise caution
Image by CryptoSlate

Curve Finance front end UI compromised following DNS hack – users advised to exercise caution

Over $500k has been stolen from Curve finance as the front end is compromised through an attack taking control of its nameserver.

Update: Curve has announced the issue has been fixed and says it is safe to use again. Follow up article can be found here

Samczsun, a researcher at Paradigm, reported that the Curve Finance front end had been compromised, with over $500k stolen within a matter of minutes.

The official Curve Finance Twitter had confirmed the news stating:

The founder of Rotkiapp, Lefteris Karapetsas, theorized that “It's DNS spoofing. Cloned the site, made the DNS point to their ip where the cloned site is deployed and added approval requests to a malicious contract.” Curve retweeted the theory in apparent support before following up with a further announcement;

Article context

Mentioned in this article

Related Asset Curve DAO Token #83 CRV $0.32 24-hour change: down 0.71% Loading price history… 24H Down 0.71% 7D Up 32.66% 30D Up 53.15% Related Person Paolo Ardoino CEO · Tether Limited