{"id":61000,"date":"2023-10-06T14:49:33","date_gmt":"2023-10-06T18:49:33","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=61000"},"modified":"2023-10-06T14:52:50","modified_gmt":"2023-10-06T18:52:50","slug":"web3-platform-galxe-protocol-experiences-dns-attack","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/web3-platform-galxe-protocol-experiences-dns-attack\/","title":{"rendered":"Web3 Platform Galxe Protocol Experiences DNS Attack"},"content":{"rendered":"\n<p>On October 6, the website of <a href=\"https:\/\/coinscreed.com\/staging\/web3-community-shares-tips-for-a-successful-gamefi-project.html\" target=\"_blank\" rel=\"noreferrer noopener\">Web3 community<\/a> platform Galxe was inactive for approximately an hour. Galxe reported on X (Twitter) that its website was down; although it has been restored, the company still warns against using it. <\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"582\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/image-20-1024x582.png\" alt=\"Web3 Platform Galxe Protocol Experiences DNS Attack\" class=\"wp-image-61007\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/image-20-1024x582.png 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/image-20-300x171.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/image-20-768x437.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/image-20-18x10.png 18w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/image-20-750x426.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/image-20.png 1059w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Web3 Platform Galxe Protocol Experiences DNS Attack<\/figcaption><\/figure>\n\n\n\n<p>Forty minutes later, it posted an update verifying that a security breach had compromised the company's Domain Name System (DNS) record. It advised against visiting its website until the issue is resolved.<\/p>\n\n\n\n<p>At the time of writing, Galxe has yet to confirm that its website is secure again. Some X-posters reported that Google had barred the website after its restoration.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Dear Galxe Community,<br><br>We recognize the impact that recent events have had upon our users and are quickly working to take remedial action. The Galxe security team continues to take an aggressive approach to protect your data, funds and digital assets.<br><br>Steps You Should Take:<br>\u2757\ufe0fDo\u2026<\/p>&mdash; Galxe (@Galxe) <a href=\"https:\/\/twitter.com\/Galxe\/status\/1710338105939521880?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">October 6, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>An explanation of a Web3 cybersecurity service:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>\u201cTheir DNS records have been modified to redirect to a phishing web-site that drains users wallets.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p>ZachXBT, a crypto-detective, has reported that Galxe is the victim of a theft. After the Galxe website was brought back online, the wallet linked to the exploit by ZachXBT continued to collect funds, and at 17:15 UTC, its balance hovered around $160,000.<\/p>\n\n\n\n<p>ZachXBT suggested connecting the Galxe exploiter and the September 19 Balancer protocol attacker. This was the second attack against <a href=\"https:\/\/coinscreed.com\/staging\/balancer-recovers-from-dns-attack-warns-of-fi-domain-risks.html\">Balancer <\/a>within a month.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">\ud83d\udea8Once you connect to Galxe, you will be prompted for approval.<br>If you approve by logging in to WEB3 as usual, all assets will be removed.<br>Please RT and spread the word. <a href=\"https:\/\/t.co\/W51Bdd78KU\" target=\"_blank\">pic.twitter.com\/W51Bdd78KU<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; ZORBA\u06de (@OHzorba) <a href=\"https:\/\/twitter.com\/OHzorba\/status\/1710321704952648029?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">October 6, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>The second attack on Balancer resulted in $238,000 in damages. The Balancer team described the incident as a social engineering attack by Angel Drainer, a <a href=\"https:\/\/coinscreed.com\/staging\/how-to-get-the-most-out-of-your-crypto-wallet.html\" target=\"_blank\" rel=\"noreferrer noopener\">crypto wallet<\/a> drainer on its DNS server. SlowMist, a blockchain security company, suggested that the perpetrator had ties to Russia.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">$148k has already been stolen by the Galxe hacker.<br><br>The hacker is using the same smart contract on 10 networks:<br><br>0x00008c6dc619b0ea53dd8d02b58bb726afc40000<br><br>Please revoke this smart contract ASAP on:<br><br>\u274d Ethereum<br>\u274d Optimism<br>\u274d Arbitrum<br>\u274d BNB Chain<br>\u274d Base<br>\u274d Polygon<br>\u274d\u2026 <a href=\"https:\/\/t.co\/iUyAenfJPu\" target=\"_blank\">pic.twitter.com\/iUyAenfJPu<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; FIP Crypto | Footprint (@fipcrypto) <a href=\"https:\/\/twitter.com\/fipcrypto\/status\/1710329831307768141?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">October 6, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>According to a recent report from the <a href=\"https:\/\/immunefi.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">security platform Immunefi<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>, Web3 initiatives suffered a significant increase in losses during the third quarter of this year compared to the same period in 2022. <\/p>\n\n\n\n<p>In the third quarter of 2023, attacks increased from 30% to 76% year-over-year, and losses approached $686 million. September 25 Mixin breach resulted in the period's most significant loss.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On October 6, the website of Web3 community platform Galxe was inactive for approximately an hour. Galxe reported on X (Twitter) that its website was down; although it has been restored, the company still warns against using it. Forty minutes later, it posted an update verifying that a security breach had compromised the company&#8217;s Domain [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":61007,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[9619],"tags":[16669,16668,6795],"class_list":["post-61000","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-web3-news","tag-dns-attack","tag-galxe-protocol","tag-web3-2"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/image-20.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/61000","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=61000"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/61000\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/61007"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=61000"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=61000"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=61000"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}