Crypto hackers siphoned $302M in May alone as DNS attacks and code vulnerabilities expose fatal flaws in DeFi security—and it's getting worse.
According to the latest official statement of Curve Finance, it is "very likely" to permanently switch to the use of curve.finance domain names. At present, the original domain name service provider has not properly responded to the problem, indicating that the original curve.fi domain name DNS problem may be difficult to recover.
据Curve Finance官方最新发文称,“极有可能”永久转向使用curve.finance域名,目前原域名服务商仍未妥善回应问题,表明原curve.fi域名DNS问题或难以恢复。
The founder of SlowMist, Cosine, wrote that Curve's current DNS hijacking problem has not been solved, and the attackers behind the scenes have also faked the wallet pop-up window to fish for mnemonic words, which is more subtle. This time, the problem again points to the domain name service provider iwantmyname, which caused a similar incident in 2022.
慢雾创始人余弦发文称,Curve当前DNS劫持问题仍未解决,幕后攻击者还通过伪造钱包弹窗钓取助记词,攻击手法更加隐蔽。此次问题再次指向域名服务商iwantmyname,该服务商曾在2022年也引发类似事件。
5月13日消息,DeFi 协议 Curve 发布今日凌晨「官网 DNS 遭劫持」事件后续公告:智能合约或内部系统均未遭到入侵,协议本身仍保持运行和安全,用户资金安全无虞。此次事件并未影响协议的基础设施,且仅局限于 DNS 层。用户仍需避免与遭影响域名进行交互,直至官方更新通过 Curve Finance 的认证沟通渠道发布。
Decentralized finance (DeFi) protocol Curve Finance has warned that hackers have again hijacked its Domain Name System (DNS), directing users to malicious websites. This is the second attack on its infrastructure in a week, and the team warned X on May 12, "curve.fi DNS may be hijacked. Do not interact!" In a subsequent response to a user who asked whether it was a hack or a hijacking, the Curve team said that when the user tried to access, the site "pointed to the wrong Internet Protocol Addres...
去中心化金融(DeFi)协议Curve Finance警告称,黑客再次劫持了其域名系统(DNS),将用户引导至恶意网站。这是其基础设施在一周内第二次遭到攻击,该团队在5月12日对X的警告中称,“curve.fi的DNS可能被劫持了。不要进行交互!” 在随后回复一位询问这是黑客攻击还是劫持的用户时,Curve团队表示,当用户尝试访问时,该网站“指向错误的IP地址”。DNS就像一个目录,将域名...
据官方消息,Curve Finance表示,其官方X(推特)账号遭遇攻击,账号访问权限已完全恢复。 在此澄清:此次事件仅限于 X 账号的安全被破坏,Curve的其他任何账户均未受到影响。Curve未发现平台存在任何安全问题,用户资金未受到损失,也没有用户因黑客发布的钓鱼链接而中招。所有Curve系统目前仍在正常运行中。 Curve仍在继续调查事件原因,并将在必要时发布更新。
Curve tweeted that its official X account has been restored to control. Previously, Curve founder Michael Egorov tweeted that Curve's official X account has been hacked, please do not click any links.
Curve 发推表示,其官方 X 账户已恢复控制。此前消息,Curve 创始人 Michael Egorov 发推表示,Curve 官方 X 账户遭黑客攻击,请勿点击任何链接。
Curve Finance's X account is suspected to have been hacked, please do not click any link it posted. Curve X account released a link to start the first round of CRV airdrops.
Curve Finance 的 X 账号疑似被黑,请勿点击其发布的任何链接。Curve X账号发布启动首轮 CRV 空投链接。
CrossCurve, a cross-chain DeFi protocol, announced the completion of a new round of financing of $1 million. Coinbase investors Tim Draper, 1inch Lianchuang, and GBV Capital participated. As of now, the company's total financing has reached $9.50 million. It is reported that the new funds will be used to build a decentralized and unified cross-chain liquidity and incentive mechanism infrastructure based on Curve AMM. CrossCurve MetaLayer.