Cryptocurrency
"Top DEXs Aerodrome, Velodrome hit with front-end compromise, urge users to avoid main domains"
Primary Source ↗Blockchain(s)
Ethereum
Incident Details
Attackers redirected users intending to visit the websites for the decentralized exchanges Aerodrome and Velodrome to their own fraudulent versions using DNS hijacking, after taking control of the websites’ domains. The platforms urged users not to visit the websites as they worked to regain control.This is the second time such an attack has happened to these same platforms, with another DNS hijacking incident occurring almost exactly two years ago. In that instance, users lost around $100,000 when submitting transactions via the scam websites.
Technical Details
- Initial Attack Vector
- DNS hijacking / domain takeover (front-end compromise)
- Vendor / Product
- Aerodrome and Velodrome
Timeline
- 2025-11-22 Breach occurred
- 2025-11-22 Publicly disclosed