
Aerodrome Finance, a leading decentralized exchange on Coinbase’s Base network with $400 million in total value locked, was targeted in a front-end attack late Friday, prompting urgent warnings for users to avoid its primary domains.
The incident appears to be a DNS hijacking of Aerodrome’s centralized domains, which allowed attackers to reroute users to lookalike phishing sites designed to trick them into signing malicious wallet transactions to separate them from their funds. Users are advised to instead rely on Aerodrome’s decentralized domains. Aerodrome has asked My.box, the domain provider, to contact them over a potential exploit of their systems.
These attacks do not compromise the underlying smart contracts, which manage user funds and protocol logic on-chain. At the time of writing, it’s unconfirmed whether the attack has led to any losses or how many users have been affected. Liquidity pools and protocol treasuries remain intact, according to Aerodrome.
Aerodrome's team has been posting real-time updates on X, urging users not to access the compromised domains, aerodrome.finance and aerodrome.box, and instead use decentralized ENS mirrors like aero.drome.eth.limo. To reduce risk, the team recommends revoking recent token approvals using tools like Revoke.cash and avoiding signing any transactions from unverified domains.
New attack
Aerodrome has experienced similar front-end attacks before, including two in late 2023 that resulted in approximately $300,000 in user losses.
This latest attack comes just days after Aerodrome announced a merger with Velodrome, consolidating liquidity across Base and Optimism under the new “Aero” ecosystem. Despite the disruption, the AERO token price remained stable at around $0.67, up 2% over the last 24 hours.
The investigation is ongoing.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。