• bitcoinBitcoin (BTC) $ 75,257.00
  • ethereumEthereum (ETH) $ 2,313.55
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 1.42
  • bnbBNB (BNB) $ 625.43
  • usd-coinUSDC (USDC) $ 0.999894
  • solanaSolana (SOL) $ 85.12
  • tronTRON (TRX) $ 0.328846
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • dogecoinDogecoin (DOGE) $ 0.094763
  • whitebitWhiteBIT Coin (WBT) $ 54.56
  • usdsUSDS (USDS) $ 0.999848
  • hyperliquidHyperliquid (HYPE) $ 41.34
  • leo-tokenLEO Token (LEO) $ 10.16
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • cardanoCardano (ADA) $ 0.246970
  • bitcoin-cashBitcoin Cash (BCH) $ 441.10
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • chainlinkChainlink (LINK) $ 9.24
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • moneroMonero (XMR) $ 350.68
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • memecoreMemeCore (M) $ 3.41
  • canton-networkCanton (CC) $ 0.153957
  • stellarStellar (XLM) $ 0.168373
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • ethena-usdeEthena USDe (USDE) $ 0.999659
  • zcashZcash (ZEC) $ 307.93
  • susdssUSDS (SUSDS) $ 1.08
  • daiDai (DAI) $ 0.999678
  • usd1-wlfiUSD1 (USD1) $ 0.999752
  • litecoinLitecoin (LTC) $ 54.97
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • paypal-usdPayPal USD (PYUSD) $ 0.999816
  • avalanche-2Avalanche (AVAX) $ 9.25
  • hedera-hashgraphHedera (HBAR) $ 0.088152
  • wethWETH (WETH) $ 2,268.37
  • suiSui (SUI) $ 0.944187
  • rainRain (RAIN) $ 0.007521
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • usdt0USDT0 (USDT0) $ 0.998824
  • the-open-networkToncoin (TON) $ 1.31
  • crypto-com-chainCronos (CRO) $ 0.069610
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,785.29
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.077813
  • pax-goldPAX Gold (PAXG) $ 4,790.57
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • bittensorBittensor (TAO) $ 243.59
  • global-dollarGlobal Dollar (USDG) $ 0.999745
  • polkadotPolkadot (DOT) $ 1.26
  • uniswapUniswap (UNI) $ 3.27
  • mantleMantle (MNT) $ 0.619941
  • skySky (SKY) $ 0.079064
  • falcon-financeFalcon USD (USDF) $ 0.998024
  • pi-networkPi Network (PI) $ 0.173376
  • nearNEAR Protocol (NEAR) $ 1.36
  • okbOKB (OKB) $ 83.19
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • aster-2Aster (ASTER) $ 0.677715
  • htx-daoHTX DAO (HTX) $ 0.000002
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • pepePepe (PEPE) $ 0.000004
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • ripple-usdRipple USD (RLUSD) $ 0.999638
  • aaveAave (AAVE) $ 90.41
  • internet-computerInternet Computer (ICP) $ 2.44
  • usddUSDD (USDD) $ 1.00
  • bitget-tokenBitget Token (BGB) $ 1.90
  • ethereum-classicEthereum Classic (ETC) $ 8.45
  • bfusdBFUSD (BFUSD) $ 0.999900
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.12
  • ondo-financeOndo (ONDO) $ 0.254157
  • kucoin-sharesKuCoin (KCS) $ 8.59
  • gatechain-tokenGate (GT) $ 7.21
  • morphoMorpho (MORPHO) $ 1.96
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • quant-networkQuant (QNT) $ 74.25
  • pump-funPump.fun (PUMP) $ 0.001822
  • united-stablesUnited Stables (U) $ 0.999868
  • ethenaEthena (ENA) $ 0.117021
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.24
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.090924
  • kaspaKaspa (KAS) $ 0.034678
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • render-tokenRender (RENDER) $ 1.77
  • algorandAlgorand (ALGO) $ 0.103156
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • cosmosCosmos Hub (ATOM) $ 1.78
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • nexoNEXO (NEXO) $ 0.892874
  • worldcoin-wldWorldcoin (WLD) $ 0.265154
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • usdtbUSDtb (USDTB) $ 0.999645
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.05
  • wbnbWrapped BNB (WBNB) $ 759.61
  • arbitrumArbitrum (ARB) $ 0.128399
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • blockchain-capitalBlockchain Capital (BCAP) $ 82.76
  • aptosAptos (APT) $ 0.932435
  • filecoinFilecoin (FIL) $ 0.926820
  • dexeDeXe (DEXE) $ 14.98
  • flare-networksFlare (FLR) $ 0.008054
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • official-trumpOfficial Trump (TRUMP) $ 2.84
  • xdce-crowd-saleXDC Network (XDC) $ 0.031122
  • beldexBeldex (BDX) $ 0.080049
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • justJUST (JST) $ 0.071979
  • vechainVeChain (VET) $ 0.007067
  • jupiter-exchange-solanaJupiter (JUP) $ 0.170607
  • ousgOUSG (OUSG) $ 114.95
  • hash-2Provenance Blockchain (HASH) $ 0.010414
  • midnight-3Midnight (NIGHT) $ 0.035780
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • yldsYLDS (YLDS) $ 0.999982
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • ghoGHO (GHO) $ 0.998816
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • stable-2​​Stable (STABLE) $ 0.025535
  • usual-usdUsual USD (USD0) $ 0.998407
  • bonkBonk (BONK) $ 0.000006
  • clbtcclBTC (CLBTC) $ 76,920.00
  • siren-2Siren (SIREN) $ 0.700058
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.53
  • true-usdTrueUSD (TUSD) $ 0.999032
  • a7a5A7A5 (A7A5) $ 0.012449
  • edgexedgeX (EDGE) $ 1.40
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.212082
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.007425
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.450501
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.693117
  • tbtctBTC (TBTC) $ 70,942.00
  • chilizChiliz (CHZ) $ 0.043997
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • adi-tokenADI (ADI) $ 4.32
  • dashDash (DASH) $ 34.09
  • euro-coinEURC (EURC) $ 1.18
  • venice-tokenVenice Token (VVV) $ 9.13
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998909
  • blockstackStacks (STX) $ 0.223914
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • layerzeroLayerZero (ZRO) $ 1.58
  • tezosTezos (XTZ) $ 0.365438
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • ether-fiEther.fi (ETHFI) $ 0.460707
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • monadMonad (MON) $ 0.032219
  • cocaCOCA (COCA) $ 1.30
  • usxUSX (USX) $ 0.999596
  • kinesis-goldKinesis Gold (KAU) $ 157.07
  • sei-networkSei (SEI) $ 0.055541
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • hastra-primePRIME (PRIME) $ 1.03
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • aerodrome-financeAerodrome Finance (AERO) $ 0.390506
  • celestiaCelestia (TIA) $ 0.387344
  • sun-tokenSun Token (SUN) $ 0.018009
  • curve-dao-tokenCurve DAO (CRV) $ 0.227862
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • decredDecred (DCR) $ 19.59
  • apenftAINFT (NFT) $ 0.00000033
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • injective-protocolInjective (INJ) $ 3.29
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • bittorrentBitTorrent (BTT) $ 0.00000032
  • gnosisGnosis (GNO) $ 120.74
  • bitcoin-svBitcoin SV (BSV) $ 15.77
  • lido-daoLido DAO (LDO) $ 0.369512
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • conflux-tokenConflux (CFX) $ 0.059879
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • spx6900SPX6900 (SPX) $ 0.328932
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • kinesis-silverKinesis Silver (KAG) $ 80.42
  • flokiFLOKI (FLOKI) $ 0.000031
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • doublezeroDoubleZero (2Z) $ 0.085520
  • jasmycoinJasmyCoin (JASMY) $ 0.005762
  • usdaiUSDai (USDAI) $ 0.999952
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • kaiaKaia (KAIA) $ 0.048133
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • fraxLegacy Frax Dollar (FRAX) $ 0.993467
  • crvusdcrvUSD (CRVUSD) $ 0.999561
  • ape-and-pepeApe and Pepe (APEPE) $ 0.000001
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • the-graphThe Graph (GRT) $ 0.024827
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06
  • syrupMaple Finance (SYRUP) $ 0.227344

Hackers impersonated eth.limo team to hijack its domain: Post-mortem

0 4

Hackers impersonated eth.limo team to hijack its domain: Post-mortem

Ethereum Name Service gateway eth.limo has revealed that the domain hijacking on Friday was caused by a social engineering attack directed against EasyDNS, its domain name service provider.

According to a postmortem published by eth.limo on Saturday, an attacker impersonated one of its team members to initiate an account recovery process with easyDNS, granting access to the eth.limo account and allowing them to alter domain settings.

“The NS records were changed and directed to Cloudflare… Once we understood that a DNS hijack had taken place, we immediately notified the community as well as Vitalik Buterin and others. We then began contacting EasyDNS in an attempt to respond to the incident,” the company said.

Eth.limo serves as a Web2 bridge, providing access to around 2 million decentralized websites using the .eth domain name. Hijacking the service could allow an attacker to redirect users to malicious websites. Ethereum co-founder Vitalik Buterin warned users Friday to avoid his blog until the incident was resolved.

Mark Jeftovic, CEO of easyDNS, has publicly accepted responsibility for the incident in its own postmortem report.

“We screwed up and we own it,” said Jeftovic on Saturday.

“This would mark the first successful social engineering attack against an easyDNS client in our 28-year history. There have been countless attempts.”

Both companies have pointed to the Domain Name System Security Extension (DNSSEC) in thwarting the hacker’s attempts to do further damage.

The attacker couldn’t produce valid cryptographic signatures, so Domain Name System resolvers rejected the attacker’s forged DNS responses, causing users to see error messages instead of being redirected to malicious sites.

“DNSSEC was enabled for their domain when the attackers attempted to flip their nameservers, presumably to effect some manner of phishing or malware injection attack, DNSSEC-aware resolvers, which most are these days, began dropping queries,” Jeftovic said.

Hackers impersonated eth.limo team to hijack its domain: Post-mortem

Source: eth.limo

In its postmortem, eth.limo noted that because the attacker lacked the signing keys, they were unable to bypass the safeguards, which likely “reduced the blast radius of the hijack. We are not aware of any user impact at this time. We will provide updates if that changes.”

easyDNS makes changes since the attack

Jeftovic described the social engineering attack as “highly sophisticated,” and said easyDNS is still conducting a post-mortem on how the breach occurred, and has already begun rolling out changes to prevent a recurrence.

Hackers impersonated eth.limo team to hijack its domain: Post-mortem

Source: easyDNS

“In eth.limo’s case, we will be migrating them to Domainsure, which has a security posture more suited toward enterprise and high-value fintech domains, TLDR there is no mechanism for an account recovery on Domainsure, it’s not a thing,” he added.

“On behalf of everyone here, I apologize to the eth.limo team and the wider Ethereum community. $ENS has always had a special place in our heart as the first registrar to enable $ENS linking to web2 domains and we’ve been involved in the space since 2017.”

The eth.limo incident is the latest in a series of domain hijackings targeting crypto projects. Days earlier, decentralized exchange aggregator CoW Swap lost control of its website after an unknown party hijacked its domain.

Steakhouse Financial, a DeFi advisory and research firm, similarly disclosed at the end of March that it had lost control of its domain to an attacker.

Source

Leave A Reply

Your email address will not be published.