Curve Finance, a major decentralized finance (DeFi) protocol, suffered a DNS hijacking attack beginning around 21:30 UTC on May 12, 2025. Attackers manipulated the domain name system (DNS) records for Curve's website, redirecting users to a fraudulent site that mimicked the legitimate interface and contained malicious JavaScript wallet drainer code. The malicious dApp was hosted via Cloudflare infrastructure. The attack was strictly limited to the DNS layer and did not compromise Curve's core smart contracts or blockchain infrastructure. The project has confirmed that user funds and smart contracts remain secure. However, users were warned not to interact with the Curve website or sign any transactions until the issue was resolved, as the malicious site could prompt users to approve token transfers to attackers. Users were also advised to revoke any suspicious approvals. The incident also affected Convex Finance, which relies on data from Curve, rendering much of Convex's website non-functional, though Convex's own site remained safe. At the time of the attack, Curve's total value locked (TVL) was reported at $3 billion. During the incident, the DNS briefly resolved to Vercel (legitimate), but attackers regained control and redirected it back to the malicious Cloudflare-hosted site. The domain registrar involved was iwantmyname. Curve Finance experienced a similar DNS hijack in 2022, resulting in $570,000 in losses, and another exploit in 2023 involving Vyper programming vulnerabilities with estimated losses of $24 million. The security team has isolated the current issue, initiated an investigation, and is working with its domain registrar and partners to restore normal operations.
Curve Finance Hit by DNS Record Attack, Warns Users to Avoid Main Site ► https://t.co/vsQIEgoLBR https://t.co/vsQIEgoLBR
Curve 域名 DNS 劫持还没解决,被 iwantmyname 服务坑得有点惨...这次钓鱼团伙还在前端玩起伪装钱包弹框的欺骗伎俩,直接钓助记词...不得不说,这点够猥琐,不知道有没有上当的... https://t.co/5sM9OKHodL https://t.co/jWCKTeHULU
Curve 2022 年就因为 @iwantmyname 导致 DNS 被劫持过,这次居然还是因为这个?...😭 https://t.co/opDVjFVvgA https://t.co/Jdamjzl2Nw