Cryptocurrency

"Top DEXs Aerodrome, Velodrome hit with front-end compromise, urge users to avoid main domains"

2025-11-22 [vendor] Aerodrome and Velodrome [chain] ethereum
Primary Source ↗
Blockchain(s) Ethereum

Incident Details

Attackers redirected users intending to visit the websites for the decentralized exchanges Aerodrome and Velodrome to their own fraudulent versions using DNS hijacking, after taking control of the websites’ domains. The platforms urged users not to visit the websites as they worked to regain control.This is the second time such an attack has happened to these same platforms, with another DNS hijacking incident occurring almost exactly two years ago. In that instance, users lost around $100,000 when submitting transactions via the scam websites.

Technical Details

Initial Attack Vector
DNS hijacking / domain takeover (front-end compromise)
Vendor / Product
Aerodrome and Velodrome

Timeline

  1. 2025-11-22 Breach occurred
  2. 2025-11-22 Publicly disclosed