{"id":59851,"date":"2023-09-21T06:57:12","date_gmt":"2023-09-21T10:57:12","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=59851"},"modified":"2023-09-21T06:57:16","modified_gmt":"2023-09-21T10:57:16","slug":"balancer-recovers-from-dns-attack-warns-of-fi-domain-risks","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/balancer-recovers-from-dns-attack-warns-of-fi-domain-risks\/","title":{"rendered":"Balancer Recovers from DNS Attack, Warns of .fi Domain Risks"},"content":{"rendered":"\n<p>Balancer has recovered its domain after a <a href=\"https:\/\/coinscreed.com\/staging\/defi-protocol-balancer-frontend-under-attack.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">DNS attack<\/a> that compromised its website and led to the loss of $240,000 in crypto. The attack resulted from a social engineering attack on EuroDNS, the domain registrar for .fi domains. Balancer is considering moving to a more secure registrar and warns other projects to do the same.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"620\" height=\"375\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/DNS_Security_domain-.jpg\" alt=\"Balancer Recovers from DNS Attack, Warns of .fi Domain Risks\" class=\"wp-image-59857\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/DNS_Security_domain-.jpg 620w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/DNS_Security_domain--300x181.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/DNS_Security_domain--18x12.jpg 18w\" sizes=\"(max-width: 620px) 100vw, 620px\" \/><\/figure>\n\n\n\n<p>A DNS attack is a type of cyberattack that exploits the Domain Name System (DNS), which is the system that translates domain names into IP addresses. <\/p>\n\n\n\n<p>By hijacking or spoofing the DNS records, an attacker can redirect users to a malicious website that looks like the legitimate one.<\/p>\n\n\n\n<p>This happened to Balancer on Sept. 19, when its website\u2019s frontend was compromised by an unknown hacker who used a social engineering attack on EuroDNS, the domain registrar for .fi domains. <\/p>\n\n\n\n<p><a href=\"https:\/\/my.eurodns.com\/login\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">EuroDNS<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> is a Luxembourg-based company that provides domain name registration and DNS services.<\/p>\n\n\n\n<p>The hacker was able to gain access to Balancer\u2019s domain and redirect users or their transactions to a phishing website that looked like Balancer\u2019s interface. <\/p>\n\n\n\n<p>The hacker then induced users to approve and transfer funds to their Ethereum address using a &#8221; transferFrom &#8221; function.<\/p>\n\n\n\n<p>According to blockchain security firms SlowMist and CertiK, the hacker also used phishing contracts called Angel Drainer, which is known for draining crypto wallets. The hacker managed to steal about <strong>$238,000<\/strong> worth of crypto from unsuspecting users.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-how-balancer-recovered-from-the-attack\">How Balancer Recovered from the Attack<\/h3>\n\n\n\n<p>Balancer detected the attack and issued a public notice on Sept. 20, advising users not to interact with its website until further notice. <\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Regarding the recent DNS attack, we can confirm that the domain is now secure and back under the control of the Balancer DAO.<a href=\"https:\/\/t.co\/kNWcQADaqa\" target=\"_blank\">https:\/\/t.co\/kNWcQADaqa<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> and other <a href=\"https:\/\/t.co\/RQO6oJXEpJ\" target=\"_blank\">https:\/\/t.co\/RQO6oJXEpJ<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> subdomains are SAFE to use.<br><br>[1\/2]<\/p>&mdash; Balancer (@Balancer) <a href=\"https:\/\/twitter.com\/Balancer\/status\/1704552285395894422?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">September 20, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>It also said it was actively addressing the attack and working with all relevant parties to ensure the full recovery of its domain.<\/p>\n\n\n\n<p>After investigation, Balancer confirmed that the attack was a result of a social engineering attack on EuroDNS and not a breach of its smart contracts or backend. <\/p>\n\n\n\n<p>It also said it was exploring deprecating the .fi top-level domain (TLD) and moving to a more secure registrar. It suggested that other projects using the same TLD should do the same.<\/p>\n\n\n\n<p>On Sept. 21, Balancer announced that it had regained control over its domain and brought it back under the control of Balancer DAO, its decentralized autonomous organization. <\/p>\n\n\n\n<p>It also confirmed that its subdomains <em>\u201capp.balancer.fi\u201d<\/em> and<em> \u201cbalancer.fi\u201d<\/em> were safe to use again.<br><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">The Implications for DeFi<\/h4>\n\n\n\n<p>Balancer\u2019s attack is not the first nor the last DNS attack on DeFi protocols. In July, <a href=\"https:\/\/coinscreed.com\/staging\/pancakeswap-google-cloud-to-enhance-defi-accessibility.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">PancakeSwap<\/a> and <a href=\"https:\/\/coinscreed.com\/staging\/cream-finances-defi-platform-suffers-a-19-million-loss-as-a-result-of-a-flash-loan-hack.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Cream Finance<\/a> suffered similar attacks that compromised their websites and tried to steal users\u2019 funds. <\/p>\n\n\n\n<p>These attacks show the vulnerability of <a href=\"https:\/\/coinscreed.com\/staging\/defi-protocols-surge-in-popularity-amidst-ether-outflows.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">DeFi protocols<\/a> to DNS attacks and the need for more security measures.<\/p>\n\n\n\n<p>Balancer\u2019s attack also highlights the importance of choosing a reliable and trustworthy domain registrar and TLD for DeFi protocols. <\/p>\n\n\n\n<p>As Balancer\u2019s founder Fernando Martinelli said, <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cFor now, we (BLabs founders\/investors) don\u2019t vote to avoid any influence on the community\u2019s opinion. However, we are very excited about these swaps that generate long-term alignment between other DAOs and ours.\u201d<\/p>\n<\/blockquote>\n\n\n\n<p>Balancer is one of the leading DeFi protocols in terms of total value locked (TVL), with over <strong>$1.5 billion<\/strong> as of Sept. 22. <\/p>\n\n\n\n<p>It provides liquidity pools, portfolio management, and price sensors for DeFi users and traders. It also has its own governance token, <a href=\"https:\/\/coinmarketcap.com\/currencies\/balancer\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">BAL,<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> which gives holders voting rights in Balancer DAO.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Balancer has recovered its domain after a DNS attack that compromised its website and led to the loss of $240,000 in crypto. The attack resulted from a social engineering attack on EuroDNS, the domain registrar for .fi domains. Balancer is considering moving to a more secure registrar and warns other projects to do the same. [&hellip;]<\/p>\n","protected":false},"author":44,"featured_media":59857,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[32],"tags":[16507,1302,197,11126],"class_list":["post-59851","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto-exchange-news","tag-fi","tag-balancer","tag-defi","tag-dns-hijack"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/09\/DNS_Security_domain-.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/59851","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/44"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=59851"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/59851\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/59857"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=59851"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=59851"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=59851"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}