News

Celer Network Attack Is Causing DeFi Chaos Along With Compound Crash

Key Points:

  • Celer Network attack is causing users to malicious phishing sites, although the company assures their systems and funds are secure.
  • Hackers employed ‘front-end’ attacks by compromising DNS registrars and replacing legitimate websites with fraudulent versions to steal funds.
In a coordinated attack on Thursday, the websites of Celer Network and Compound Finance were compromised, redirecting users to malicious phishing sites.

Celer Network Attack Targeted in Phishing Websites

Celer Network informed its users four hours after the attack, warning them to avoid celer.network and cbridge.celer.network while they investigated a potential DNS domain attack. Despite the Celer Network attack, it assured that their systems and funds remained secure and promised further updates as the situation evolved.

The Celer Network attack used is known as a ‘front-end’ attack, where hackers replace the project’s legitimate website with a fraudulent version. The method does not exploit vulnerabilities in smart contract code but instead targets the domain name service (DNS) registrar. Attackers often use social engineering or financial incentives to compromise the DNS registrar, redirecting users to phishing sites.

Security Flaws in Squarespace Linked to Multiple DeFi Hacks

Security researcher Samczsun and DeFiLlama’s 0xngmi have identified the common link between the affected projects as their use of Squarespace for web hosting. 0xngmi has compiled a list of other potentially at-risk domains, highlighting a broader vulnerability in the DeFi space.

Earlier today, Compound Finance‘s frontend was similarly compromised, leading users to a phishing site at compound-finance.app. Security expert Michael Lewellen noted that this site could drain users’ funds if they interact with it, though the core Compound protocol and user deposits remain unaffected.

These attacks are part of a larger trend where hackers clone original websites, swapping out key elements to execute malicious transactions. These can transfer funds to hacker-controlled addresses or harvest token approvals. Other large DeFi projects using Squarespace, such as Pendle, Karak, Hyperliquid, and dYdX, may also be at risk of similar attacks.

Harold

With a passion for untangling the complexities of the financial world, I've spent over four years in financial journalism, covering everything from traditional equities to the cutting edge of venture capital. "The financial markets are a fascinating puzzle," I often say, "and I love helping people make sense of them." That's what drives me to bring clear and insightful financial journalism to the readers of Coincu.

Recent Posts

Crypto Market Outlook 2025 Key Factors to Watch

The Crypto Market Outlook 2025 highlights key areas: stablecoin growth, tokenization, crypto ETFs, DeFi innovation,…

43 minutes ago

Bitcoin Quantum Computing Threat Expected to Take Decades

The Bitcoin quantum computing threat is years away, but reserves already support post-quantum signatures via…

1 hour ago

Best New Meme Coins to Invest in Today: BTFD Coin Wows Investors with Unmissable Stage-7 Price Reversal as Book of Meme and Snek Crash

Don't miss BTFD Coin's Stage-7 presale dip! Find out why it's leading the pack of…

1 hour ago

Crypto Hedge Funds Banking Issues Persist Over Recent Years

A WSJ survey reveals crypto hedge funds banking issues over three years, with 120 out…

1 hour ago

GraniteShares Crypto ETFs Target U.S. Crypto-Related Stocks

GraniteShares Crypto ETFs aim to offer leveraged exposure to crypto-focused stocks like Riot Platforms and…

2 hours ago

Best New Meme Coins for Massive Return Potential: BTFD Coin’s Amazing Offer, Cat in a Dog’s World Sees Down Turn, Degen Down Double Digits

Explore the best new meme coins for massive returns, including BTFD Coin with its record-breaking…

3 hours ago

This website uses cookies.