Carding Forum
Professional
- Messages
- 2,788
- Reaction score
- 1,177
- Points
- 113
Users should avoid the Compound Finance website, which can redirect visitors to a phishing site and pose a significant security risk. This was stated by on-chain analyst ZachXBT.
Compound Finance confirmed the fact of hacking and advised not to interact with the page until further notice.
"The Compound protocol has not been affected, all funds on smart contracts are safe," project representatives assured.
The Celer Network protocol also reported hacking the website interface and the cbridge bridge.
The co-founder of the DeFiLlama 0xngmi service said that the reason lies in the vulnerability of the Squarespace site builder. It published a list of potential victims using the solution. Among them are Pendle, dYdX, Axelar, Thorchain and a number of other well-known projects.
In 2023, hackers temporarily seized control of the X Compound account to promote a phishing site.
Attackers placed ads for free tokens. It called for clicking on a link that mimics the official protocol page.
After the team's actions, the post was marked as "fraud". Four hours later, she managed to regain control of her account and delete the spam message.
*****
Opinion: Squarespace hack threatens more than 220 DeFi protocols
After an attack on DNS records hosted on Squarespace web hosting, the interfaces of approximately 228 DeFi projects remain at risk. This was announced to Decrypt by Blockaid CEO Ido Ben-Nathan.
On July 11, the incident affected Compound Finance and Celer Network, whose sites began redirecting users to phishing pages. The expert noted that the interception of DNS requests from protocols allowed attackers to use IP addresses associated with the Inferno drainer.
The use of a known malicious solution is indicated by the common on-chain and off-chain infrastructure, including smart contracts and wallets, according to Ben-Nathan.
Inferno Drainer tools allow cybercriminals to steal users funds, automatically emptying their accounts after signing malicious transactions.
The group has been trying to exploit vulnerabilities in DeFi protocols for some time, the co-founder of Blockaid emphasized. However, using a single infrastructure helps track and identify their attacks, he added.
Commenting on the Squarespace incident, the founder of Unstoppable Domains, Matthew Gould, noted that additional protection of DNS records can be provided by their verification on the blockchain. You can set up an update only through confirmation in the chain, for example, using a wallet signature, he explained.
Registrars are custodians of your domains. If they are compromised, like SquareSpace today, your website traffic can be routed without your permission to somewhere else.

Compound Finance confirmed the fact of hacking and advised not to interact with the page until further notice.
ALERT: The https://t.co/vSAGYl6wwJ URL has been compromised and is currently hosting a phishing site. DO NOT interact with the https://t.co/vSAGYl6wwJ website until further notice.
The Compound protocol itself is not impacted and all smart contract funds are safe.
— Michael Lewellen (@LewellenMichael) July 11, 2024
"The Compound protocol has not been affected, all funds on smart contracts are safe," project representatives assured.
The Celer Network protocol also reported hacking the website interface and the cbridge bridge.
PLEASE DO NOT ACCESS https://t.co/7EFaRdEOl6 and https://t.co/wQFsd2XFb9.
We are investigating a potential DNS domain attack that seems to be hitting multiple projects at the same time.
Celer system and funds are safe.
— CelerNetwork (@CelerNetwork) July 11, 2024
The co-founder of the DeFiLlama 0xngmi service said that the reason lies in the vulnerability of the Squarespace site builder. It published a list of potential victims using the solution. Among them are Pendle, dYdX, Axelar, Thorchain and a number of other well-known projects.
notable domains that are at risk:https://t.co/SxUDwsEgxChttps://t.co/ZfqPB3dvGJhttps://t.co/IQoLlDzCl7https://t.co/c8aJyZ4rZmhttps://t.co/pnFuffioeshttps://t.co/Cz4tJMHsL2https://t.co/TMSUnVTlrqhttps://t.co/PiVFKTBlMHhttps://t.co/8VtP9ituCDhttps://t.co/1n5DnS5R2B… https://t.co/399c6wO3B6
— 0xngmi (@0xngmi) July 11, 2024
In 2023, hackers temporarily seized control of the X Compound account to promote a phishing site.
FYI the @compoundfinance twitter is compromised and posting a scam link!
Check out: @RevokeCash / @web3_antivirus / @wallet_guard / @blockfence_io / @realScamSniffer
— Officer's Notes (@officer_cia) December 29, 2023
Attackers placed ads for free tokens. It called for clicking on a link that mimics the official protocol page.
After the team's actions, the post was marked as "fraud". Four hours later, she managed to regain control of her account and delete the spam message.
*****
Opinion: Squarespace hack threatens more than 220 DeFi protocols
After an attack on DNS records hosted on Squarespace web hosting, the interfaces of approximately 228 DeFi projects remain at risk. This was announced to Decrypt by Blockaid CEO Ido Ben-Nathan.
On July 11, the incident affected Compound Finance and Celer Network, whose sites began redirecting users to phishing pages. The expert noted that the interception of DNS requests from protocols allowed attackers to use IP addresses associated with the Inferno drainer.
The use of a known malicious solution is indicated by the common on-chain and off-chain infrastructure, including smart contracts and wallets, according to Ben-Nathan.
Inferno Drainer tools allow cybercriminals to steal users funds, automatically emptying their accounts after signing malicious transactions.
The group has been trying to exploit vulnerabilities in DeFi protocols for some time, the co-founder of Blockaid emphasized. However, using a single infrastructure helps track and identify their attacks, he added.
Commenting on the Squarespace incident, the founder of Unstoppable Domains, Matthew Gould, noted that additional protection of DNS records can be provided by their verification on the blockchain. You can set up an update only through confirmation in the chain, for example, using a wallet signature, he explained.
Registrars are custodians of your domains. If they are compromised, like SquareSpace today, your website traffic can be routed without your permission to somewhere else.
By creating verified onchain records for domains we can offer an extra layer of protection browsers and… https://t.co/Zgya33A4HC
— matt.crypto | matt.pudgy (@matthewegould) July 11, 2024