
A significant security breach has impacted numerous domains hosted by Squarespace, following its acquisition of Google Domains. The breach, which began on July 10, 2024, has compromised several popular Web3 and DeFi sites, including Hyperliquid, dYdX, Pendle, and Unstoppable Domains. Many of these sites were transferred to Squarespace after Google sold its domain business in June 2023. The breach has led to domain hijacking attempts, prompting warnings from various entities to avoid using affected services and to enable two-factor authentication (2FA) immediately. Vertex Protocol and Steer Protocol have confirmed that they are investigating the situation, while Karak Network and Term Labs have reported that their domains remain secure. Gnosis Multisig is also at risk but currently safe. The incident underscores the importance of robust domain security measures, with experts advising the migration of high-value domains to more secure platforms like Cloudflare or AWS. Additionally, there are concerns about wallet drainers being used in the attacks.





SEAL and other researchers have been hard at work assisting teams affected by the @squarespace domain hijacking incident. We are publishing an official security advisory to clear up any confusion. Summary: - Likely related to Google migration - Remove extra users and enable 2FA
has @squarespace still not fixed the domain hijacking? this is insanely incompetent cuz its been more than a day now and cant find any statements and seems like domains are still getting hijacked everything i found on google is from cointelegraph n stuff
The Squarespace hacks exemplify the urgency of moving domains onchain. A domain is one of the most important components of any project. It’s the gateway to the app and a core trusted piece of infrastructure by the community. https://t.co/n8SzGBd4QD 🧵 https://t.co/QBobxCE5nq