Market Cap: $2.1713T -2.52%
Volume(24h): $68.5868B 58.87%
  • Market Cap: $2.1713T -2.52%
  • Volume(24h): $68.5868B 58.87%
  • Fear & Greed Index:
  • Market Cap: $2.1713T -2.52%
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
Top News
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

Cryptocurrency News Articles

DeFi Platforms Compound Finance and Celer Network Hit by Phishing Attacks

Jul 11, 2024 at 09:05 pm

The websites of crypto lending platform Compound Finance and Celer Network have been attacked, redirecting users to a malicious phishing site

DeFi Platforms Compound Finance and Celer Network Hit by Phishing Attacks

The websites of crypto lending platform Compound Finance and Celer Network have been attacked, redirecting users to a malicious phishing site, according to multiple security researchers on Friday.

Compound, one of the longest-established decentralized finance (DeFi) applications, holds assets worth over $2 billion, according to data from DeFiLlama. Celer’s cBridge allows users to send tokens between 14 blockchains, processing over $200 million in volume last month.

Security advisor to the Compound DAO, Michael Lewellen, posted a community alert via X (formerly Twitter), urging users to avoid the platform’s website. A total of 90 minutes passed before the attack was confirmed by Compound Finance. The breach was highlighted earlier by ZachXBT via Telegram.

ALERT: The https://t.co/vSAGYl6wwJ URL has been compromised and is currently hosting a phishing site. DO NOT interact with the https://t.co/vSAGYl6wwJ website until further notice.The Compound protocol itself is not impacted and all smart contract funds are safe.

Celer Network alerted users four hours later to a similar attack that “seems to be hitting multiple projects at the same time.” Pseudonymous security researcher Samczsun suspects the breaches to have come from Squarespace. A list of other domains that may be at risk was compiled by DeFiLlama’s 0xngmi.

This type of attack, known as a “front-end” attack, is a relatively common vector for crypto hackers. The method doesn’t rely on finding a bug to exploit within the underlying smart contract code, instead simply replacing the project’s website with a malicious version.

A potential attacker must compromise the domain name service (DNS) registrar, generally using financial incentives or social engineering techniques on an employee. In response to the front-end attack that hit Curve Finance in June 2022, the CEO of Namecheap (the DNS registrar responsible) stated that a customer service agent was compromised, either being hacked or exploited with bitcoin.

Dear @iwantmyname, looks like something is compromised on your side (most likely, name servers – they seem to override what the UI tells them to serve). Please do something.For everyone else: we switched nameserver, but don't rush to use https://t.co/vOeMYOTq0l – wait a bit

Similar incidents have affected many major DeFi platforms, such as Curve Finance, Cream Finance, Pancake Swap, Balancer, Frax and Velodrome, among others.

Previous hacks often involve cloning the original website, but swapping out key elements which can lead to users’ wallets crafting malicious transactions. This could be to transfer funds directly to an address controlled by the hacker, or to “harvest” token approvals.

This approvals harvesting technique was used to devastating effect in the $120 million BadgerDAO hack of December 2021.

Over the course of 12 days, BadgerDAO users inadvertently signed malicious approval transactions which granted the exploiter permission to spend tokens directly from the victims’ wallets. Now-bankrupt Celsius was among the victims, losing 897 BTC (then valued at over $40 million) before later forfeiting $22 million in compensation due to an ‘unforced error’.

Here is the current whereabouts as well as the total loss: $120.3M (with ~2.1k BTC + 151 ETH) @BadgerDAO pic.twitter.com/fJ4hJcMWTq

Despite today’s incident, Compound’s back-end code is considered among the most secure in DeFi, with any changes requiring scrutiny via a fully on-chain governance process.

Low-effort “forks”, however, regularly find themselves exploited due to dodgy collateral or basic errors when setting up new markets.

Compound itself hasn’t been entirely without its issues in the past, though.

? Alert: @compoundfinance's Twitter account has been compromised. Do not click on any links posted from their account.A phishing link (compound-labs[.]xyz) was spotted 16 hours ago.Stay vigilant and ensure the safety of your assets by avoiding suspicious links. pic.twitter.com/yoa1RM4P4E

The project’s X account was compromised in December 2023 to spread a phishing link, promising free COMP, the project’s native token.

In September and October of 2021, a total of almost $150 million worth of COMP was accidentally distributed as excess rewards to users. Another incident the following year saw the platform’s $830 million ETH market frozen for a week.

Original source:protos

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Other articles published on Jul 28, 2026