Cronos DEX Mad Meerkat Finance Loses $2M After Front-End DNS Hijack Reroutes User Swaps
Mad Meerkat Finance, a decentralized exchange on the Cronos chain, lost more than $2 million after its front-end was compromised. It is a separate project from the similarly named Meerkat Finance on BSC.
The front-end exploit began around 7:30 PM on May 4. From that point, any user swapping tokens or adjusting liquidity on the protocol had their output funds redirected directly to the attacker's wallet instead of their own. The attack continued for roughly three hours until the team pulled the front-end offline. While it was ongoing, staff used the project's Discord to warn users away from the site — raising questions about why the compromised interface wasn't taken down sooner or blocked outright.

01What the post-mortem revealed — and didn't
The team's official post-mortem attributes the breach to a DNS attack, describing it this way:
MM.finance site was the subject of a DNS attack earlier where an attacker managed to inject a malicious contract address into the frontend code. Attacker used a DNS vulnerability to modify the router contract address in our hosted files.
Exactly how the attacker gained the access needed to pull this off remains unclear from the writeup. Discussion in the rekt.news Telegram group speculated that users may have been served a cloned version of the site, with some pointing to signs of a DNS redirect and reports of a bad SSL certificate circulating on Discord. Others in the community were more doubtful of that theory. Notably, some users had already flagged concerns via Discord before the exploit went public, but the team did not treat those warnings as serious at the time.
Regardless of the precise entry point, the attack was clearly set up in advance, with the malicious router address already tied to the attacker's wallet before transactions began flowing through it.
02How the funds were rerouted
The redirection started with a swap transaction executed at 19:28:35 UTC. From that point on, outputs from all interactions with the DEX were sent to the attacker's address rather than to users. In total, more than 600 transactions were captured this way. The attacker converted the proceeds to USDT and bridged them to Ethereum, depositing 743 ETH into Tornado Cash so far.
The post-mortem now instructs users to manually verify the router contract address — 0x145677FC4d9b8F19B5D56d1820c48e0443049a30 — before confirming any transaction.

03Aftermath
The Mad Meerkat team said it traced the funding source behind the attacker's wallet to OKX and has publicly requested help identifying the individual responsible. Affected users are set to be reimbursed out of the team's share of trading fees, with further compensation details laid out in a separate update.
This incident marks the first Cronos-based exploit to be added to rekt's leaderboard, landing at position #76.
Get new scam files the moment we publish them — usually 2–3 emails a week.