How a Squarespace Login Flaw Turned Into a Multi-Protocol Domain Hijacking Wave
A string of crypto website takeovers between July 9 and July 12, 2024 traced back not to a smart-contract bug but to something far more mundane: weak account-security defaults at web-hosting provider Squarespace, which manages domains for a large swath of the crypto industry.
CoinList caught the first attempt on July 9. According to a Krebs on Security report, the exchange spotted unauthorized access to its Squarespace account and blocked attempts to pivot into other connected third-party services before any damage was done. That intrusion turned out to be an early tremor ahead of a much larger event.

Over the following three days, the same technique hit a wide range of higher-profile targets, including Celer Network, Compound Finance, Pendle Finance, and dozens of additional projects catalogued in a running list compiled by 0xngmi. All of them shared Squarespace as a domain host, and all were exposed through the same weakness in that platform rather than through any flaw in their own protocols.
Mechanics of the intrusion
Attackers first obtained unauthorized entry into victims' Squarespace accounts — access that investigators suspect was made easier by lingering gaps left over from Squarespace's takeover of Google Domains. Squarespace acquired Google Domains in June 2023, with the deal closing on September 7, 2023, and the migration of millions of domains that followed appears to have created openings that had not been fully closed by the time of the attacks.
Once inside an account, the attackers altered email-forwarding rules so that all incoming mail routed to addresses they controlled. That gave them visibility into password-reset emails for connected third-party services. From there they carried out a form of DNS hijacking, deliberately going after accounts likely to hold administrative privileges. Intercepting those reset links let them seize control of the associated services — enough access to either drain funds directly or plant malicious code on the affected websites to target visiting users.
Scale and response
By July 12, what had looked like an isolated incident had turned into an industry-wide scramble, with dozens of DeFi platforms, blockchain infrastructure providers, and other Web3 projects discovering their sites had been compromised. New cases surfaced by the hour, each one a fresh risk to user funds and to trust in the affected brands.
Squarespace's handling of the incident drew heavy criticism for being sluggish, especially given that the company had already been notified of the breach by CoinList on July 9 yet was slow to publicly acknowledge the issue or advise affected customers.
Guidance from researchers
Security researchers samczsun, tayvano, and AndrewMohawk circulated a set of mitigation steps for teams using Squarespace:
Short term, for Squarespace accounts:
- Turn on 2FA for domain-owner accounts.
- Rotate to unique, new passwords.
- Remove contributors who no longer need access.
- Confirm remaining contributors also have 2FA and unique passwords.
Short term, for Google Workspace:
- Disable reseller access where Workspace was originally purchased through Google Domains.
Longer term, teams were urged to move to a registrar offering:
- Hardware-token MFA.
- Fine-grained permission controls for domain managers.
- Accessible audit logs.
- Alerts for sensitive account actions.

Suggested registrars included Cloudflare Registrar, Amazon Route 53, and dnsimple for smaller teams, with MarkMonitor and CSC recommended at the enterprise level. Researchers also pointed to layered defenses such as CoinList's combination of YubiKeys and monitoring tooling, and stressed the need to periodically reassess attack surface — particularly after infrastructure changes — since Web2 providers may not account for crypto-specific threat models.
The Security Alliance published a retrospective detailing how the industry coordinated its response, and 0xngmi's gist of at-risk Squarespace domains circulated widely as a reference for teams checking their exposure.
Even so, the warnings didn't fully stop the bleeding: dYdX's domain was hijacked on July 23 despite already appearing on that watch list.
For a technical breakdown of the payload used against one of the victims, alp1n3.eth published an analysis of the "Inferno Drainer" malicious JavaScript deployed in the Compound Finance compromise.
The episode underscored a recurring theme in crypto security: protocols can harden their smart contracts extensively and still be undone by a single point of failure sitting outside the chain entirely — the Web2 infrastructure, like domain registrars, that most projects still depend on. As some observers noted afterward, half-jokingly referencing Crowdstrike's $10 Uber Eats gift-card apology for a separate outage, no token of goodwill from a hosting provider offsets the cost of a coordinated, industry-wide breach.
Credit: Michael Coates, Security Alliance, 0xngmi, alp1n3.eth, Krebs on Security
Get new scam files the moment we publish them — usually 2–3 emails a week.