Curve Finance Suffers DNS Attack, Redirects Users to Malicious Site
- Curve Finance’s website was compromised through a DNS attack, redirecting users to a fraudulent site.
- The attack involved altering DNS records to mimic Curve’s interface with malicious scripts.
- This is not the first incident; in 2022, a similar hijack resulted in $570,000 in losses.
- A separate exploit in 2023 involving Vyper vulnerabilities led to estimated losses of $24 million.
- Curve confirmed the smart contracts remain secure and user funds are safe despite the breach.
Curve Finance experienced a DNS compromise that redirected users to a malicious site. Despite this, their smart contracts were not affected, ensuring user funds remained secure. Previous incidents include significant financial losses due to similar attacks and programming vulnerabilities.
Source (2.6)https://decrypt.co/319414/curve-finance-dns-record-attack?rand=52368