Curve – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Wed, 14 May 2025 03:32:19 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Curve – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Curve Finance moves to new domain after DNS attack exposes security risks https://earlybirdsinvest.com/curve-finance-moves-to-new-domain-after-dns-attack-exposes-security-risks/ https://earlybirdsinvest.com/curve-finance-moves-to-new-domain-after-dns-attack-exposes-security-risks/#respond Wed, 14 May 2025 03:32:18 +0000 https://earlybirdsinvest.com/curve-finance-moves-to-new-domain-after-dns-attack-exposes-security-risks/

Curve Finance is moving permanently to a new web domain following a targeted DNS attack that exposed users to phishing risks.

On May 13, the DeFi protocol confirmed that it will operate on Curve.finance, replacing the compromised Curve.fi.

The protocol explained that it was making the move because of the prolonged downtime and limited support from .fi domain registrars.

It stated:

“[The] .fi [domain] will be down for too long / no point of moving back. Also registrars who can hold .fi are somewhat not as great as those who can deal with .finance.”

On May 12, hackers hijacked the DNS records for Curve.fi, redirecting visitors to a malicious website that mimicked the protocol’s interface. This fake site attempted to trick users into signing wallet-draining transactions.

Following the incident, Curve said that the issue was contained at the DNS level and that no internal systems were breached.

However, the compromised website was left on for several hours as the domain registrar, iwantmyname, failed to respond to community complaints.

Curve said:

“[The registrar’s] response time is totally unacceptable: we need access to curve [.] fi taken away from hackers and the incident to be investigated.”

Speaking on this, Yu Xian, the founder of blockchain security firm Slowmist, highlighted the risk that the issue could have caused, noting that:

“The phishing gang [was] playing dirty tricks at the front end with fake wallet pop-up scams, directly fishing for mnemonic phrases… I have to say, this is pretty sleazy.”

The compromised domain name has been frozen since the attack.

Curve’s security challenges

In 2022, the protocol suffered a similar DNS hijack, which led to user losses totaling approximately $530,000. Notably, the firm was using the same registrar, iwantmyname, at the time of the attack.

Meanwhile, the recent DNS attack comes just over a week after a separate security event in which a hacker temporarily took over Curve’s X account.

On May 5, a hacker took over the platform’s social media handle to post phishing links. The team regained control of the account quickly and said no user funds were impacted.

Meanwhile, security experts emphasized that the back-to-back incidents show that attackers are shifting focus from code exploits to infrastructure-based vulnerabilities.

This year, the crypto industry has lost around $2 billion to malicious actors who have exploited centralized exchanges like Bybit and several DeFi protocols.

Mentioned in this article
]]>
https://earlybirdsinvest.com/curve-finance-moves-to-new-domain-after-dns-attack-exposes-security-risks/feed/ 0 36101
Tron says DAO X hack cost victims $45K, Curve Finance also hit https://earlybirdsinvest.com/tron-says-dao-x-hack-cost-victims-45k-curve-finance-also-hit/ https://earlybirdsinvest.com/tron-says-dao-x-hack-cost-victims-45k-curve-finance-also-hit/#respond Tue, 06 May 2025 03:58:40 +0000 https://earlybirdsinvest.com/tron-says-dao-x-hack-cost-victims-45k-curve-finance-also-hit/

A hacker who took over the Tron DAO X account is estimated to have made around $45,000 in improperly solicited funds, according to a spokesperson from Tron. 

Speaking to Cointelegraph, the Tron public relations team confirmed that on May 2, the Tron DAO account posted a contract address and sent direct messages to solicit payments in exchange for promotional advertising on the Tron account.

“Our security team quickly identified the intrusion and cut off access to the hacker, but we ask the community to continue to be vigilant. We will never ask anyone for payments like this via DM or otherwise,” they said. 

The team said that based on the illicit contract address the hacker posted, the amount improperly solicited appeared to be around $45,000. 

Asked whether the same hacker could be responsible for the supposed New York Post’s X account hack on May 3, the Tron team told Cointelegraph that there “appear to be some similarities” between the two security incidents; however, they also cautioned that the investigation is ongoing and “any definitive connection would be premature.” 

After regaining access, Tron DAO said in a May 2 X update that they suspect the hack resulted from a team member being “targeted in a malicious social engineering attack, which led to their account being compromised.”

Source: Tron DAO

“Even after the perpetrator was logged out and our access restored, they continued contacting others, offering posts from our main account in exchange for payment,” Tron DAO said.

The Tron team is still investigating and says they are in contact with law enforcement. Tron founder Justin Sun also accused crypto exchange OKX of failing to act on a law enforcement request to freeze stolen funds connected to the attack.

OKX founder and CEO Star Xu has publicly denied the allegation, and Sun has removed the original post with the accusation.  

Curve Finance joins list of X account hacks 

Decentralized lending protocol Curve Finance also recently suffered an X account takeover by a bad actor, adding to the growing list of high-profile firms and individuals “silently” accessed by social media hackers. 

In a now-deleted May 5 X post, a scammer posing as Curve Finance shared a link to a CRV airdrop with a weeklong registration period, which some eagle-eyed X users quickly suspected could be fraudulent.

Curve Finance founder Michael Egorov confirmed in a reply to analyst CrediBULL Crypto that it was a bad actor posting sham links so far, “No other account appears to be hacked — the control over X account was just silently taken by someone.”

Source: CrediBULL Crypto

The Curve Finance team has since regained access with the help of a team that included the cybersecurity group SEAL, and found that aside from posting scam links, the hacker also blocked some users who flagged the account takeover, including CrediBULL Crypto.

The cause of the hack has yet to be shared publicly, but in response to a user’s query, the Curve finance team said it’s still “unclear how account” access was taken, and there was “No sign of any client-side compromise.”

Source: Curve Finance

Other high-profile X account hacks

A slew of other high-profile X accounts have also been taken over by bad actors this year. On April 15, a member of the UK’s Parliament, Lucy Powell, had her account taken over to promote a scam crypto token called the House of Commons Coin (HOC).

Crypto data aggregator Kaito AI and its founder, Yu Hu, were the victims of an X social media hack on March 15, when scammers posted that the Kaito wallets were compromised and users’ funds were at risk.

Related: Breaking Bad star’s X account hacked for memecoin scheme

Meanwhile, Pump.fun’s X account was also hacked on Feb. 26 and promoted several fake tokens, including a fraudulent governance token for the platform called Pump.

Magazine: Bitcoin to $1M ‘by 2029,’ CIA tips its hat to Bitcoin: Hodler’s Digest, April 27 – May 3

]]> https://earlybirdsinvest.com/tron-says-dao-x-hack-cost-victims-45k-curve-finance-also-hit/feed/ 0 34645