CryptoReal
CASE FILE — Aug 10, 2022

DNS Hijack on Curve Finance's Front End Leads to $575K in Losses

On August 9, 2022, Curve Finance's main interface, curve.fi, was compromised through a DNS hijack, first flagged publicly by a security researcher. Visitors were served a prompt to approve a malicious contract, and those who signed off had funds drained from their wallets.

Roughly $575,000 was lost by users who granted the approval. The stolen assets were funneled toward centralized exchanges and Tornado Cash — a routing choice made despite the mixer's status under OFAC sanctions.

The project's backup interface, curve.exchange, was never affected, and the Curve team redirected users there while the hijack was being resolved. The attacker's cloned site was taken down relatively quickly, though the team later noted that some nameservers still needed to be corrected.

As with most DNS-level incidents, establishing exactly what happened rests largely on the registrar's own account, since there is no on-chain trail to independently verify it. iwantmyname, the registrar involved, had not issued public comment on the root cause at the time. Curve, for its part, said it believed the underlying nameserver itself had been compromised rather than Curve's own account being breached.

Curve founder and CEO Michael Egorov gave rekt.news his own account of events:

"Well for now I can say that dns registrar iwantmyname had their ns compromised No account hack Switched the ns Besides a good bunch of hacked money frozen by centralized services What could be done better.. we should try to go away from web2 things like dns tbh, that would be the best"

Additional detail on the incident was shared separately.

Anyone who interacted with the compromised interface was urged to revoke their approval to the malicious contract at 0x9eb5f8e83359bb5013f3d8eee60bdce5654e8881 without delay.

Funds flowed to the attacker's wallet, 0x50f9202e0f1c1577822bd67193960b213cd2f331. In total, 340 ETH — about $575,000 — was stolen and distributed across FixedFloat (292 ETH, of which 112 ETH was later frozen), Binance (20 ETH), and Tornado Cash (27.7 ETH).

The episode underscores a broader weakness: for most users, DeFi's practical security is only as strong as the conventionally-hosted front end sitting in front of the smart contracts. As back-end contracts for established protocols have grown more battle-tested, attackers have increasingly shifted their focus to front ends instead — a vector that exploits users' trust in a project's contracts while sidestepping the actual security of the interface they click through.

Absent genuine decentralization at the interface layer, approval-harvesting attacks of this kind are likely to keep recurring, as already seen with BadgerDAO, Mad Meerkat Finance, and, not long before this incident, the Namecheap breach that hit front ends across four different DeFi protocols. No amount of smart-contract auditing or decentralized governance changes the fact that a project's reputation can still take a hit because of a web2 vendor's failure.

Outside of watching for unexpected site changes, protocols and their users remain largely dependent on trusting a third-party company's infrastructure and personnel. A more durable fix would involve protocols serving their front ends through IPFS and ENS rather than relying on conventional DNS providers — since most users have neither the interest nor the means to interact with smart contracts directly, treating interface security as an afterthought is a risk the sector can ill afford.

Curve FinanceDNS hijack
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.