{"id":94714,"date":"2024-09-25T09:57:20","date_gmt":"2024-09-25T13:57:20","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=94714"},"modified":"2024-09-25T09:59:06","modified_gmt":"2024-09-25T13:59:06","slug":"ether-fi-prevents-domain-account-takeover","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/ether-fi-prevents-domain-account-takeover\/","title":{"rendered":"ETher.fi Prevents Domain Account Takeover, Secures User Funds"},"content":{"rendered":"\n<p>Ether.fi asserts security updates and partners for preventing a <a href=\"https:\/\/coinscreed.com\/staging\/x-security-questioned-after-unauthorized-us-sec-account-access.html\" target=\"_blank\" data-type=\"post\" data-id=\"68655\" rel=\"noreferrer noopener\">domain account takeover<\/a> before user funds were taken.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1260\" height=\"756\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/ETher.fi-Prevents-Domain-Account-Takeover-Secures-User-Funds-1.png\" alt=\"ETher.fi Prevents Domain Account Takeover, Secures User Funds\" class=\"wp-image-94729\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/ETher.fi-Prevents-Domain-Account-Takeover-Secures-User-Funds-1.png 1260w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/ETher.fi-Prevents-Domain-Account-Takeover-Secures-User-Funds-1-300x180.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/ETher.fi-Prevents-Domain-Account-Takeover-Secures-User-Funds-1-1024x614.png 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/ETher.fi-Prevents-Domain-Account-Takeover-Secures-User-Funds-1-768x461.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/ETher.fi-Prevents-Domain-Account-Takeover-Secures-User-Funds-1-860x516.png 860w\" sizes=\"(max-width: 1260px) 100vw, 1260px\" \/><\/figure>\n\n\n\n<p>Ether.fi, a decentralized finance (DeFi) staking platform, reported that no user funds were compromised following a recent domain takeover attempt.<\/p>\n\n\n\n<p>On Sept. 24, the protocol experienced an attempted domain account hijacking through their registrar, Gandi.net. Fortunately, the attack was stopped before any significant damage could be done.<\/p>\n\n\n\n<p>The Ether.fi team confirmed that attackers were unable to deploy a malicious decentralized application (DApp) on any of their domains.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">On September 24, <a href=\"https:\/\/t.co\/gbHcksxzp2\" target=\"_blank\">https:\/\/t.co\/gbHcksxzp2<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> experienced a security incident involving our domain registrar, <a href=\"https:\/\/t.co\/hW50MConP9\" target=\"_blank\">https:\/\/t.co\/hW50MConP9<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><br><br>We\u2019re glad to report that all funds are safe, and the attackers at no point presented a compromised dapp on any <a href=\"https:\/\/t.co\/gbHcksxzp2\" target=\"_blank\">https:\/\/t.co\/gbHcksxzp2<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> related\u2026<\/p>&mdash; ether.fi (@ether_fi) <a href=\"https:\/\/twitter.com\/ether_fi\/status\/1838735907588820993?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">September 25, 2024<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Ether.fi's Response to the Attack<\/h2>\n\n\n\n<p>The breach began on Sept. 24 when Ether.fi received a recovery notification email from Gandi.net at 4:38 pm UTC. <\/p>\n\n\n\n<p>Upon further verification using security measures like <em>&#8220;SPF, DKIM, and DMARC authentication records,&#8221;<\/em> the team realized the email was part of the attack.<\/p>\n\n\n\n<p>According to <a href=\"https:\/\/etherfi.gitbook.io\/etherfi\/security\/sep-24-incident-attempted-domain-account-takeover\" target=\"_blank\" rel=\"noreferrer noopener\">an official post <span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>on Ether.fi\u2019s Gitbook, <em>&#8220;it was established an attacker attempted to use the legitimate Gandi recovery flow to gain access to etherfi\u2019s Gandi account.&#8221;<\/em> Ether.fi quickly contacted Gandi through various channels, and by 7:30 pm UTC, the account was secured to prevent further tampering.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Security Enhancements<\/h2>\n\n\n\n<p>Prior security upgrades helped mitigate the domain takeover threat. Weeks before the attack, Ether.fi had observed a rise in similar exploitation attempts across other platforms.<\/p>\n\n\n\n<p>As a result, the protocol upgraded its key systems to require hardware authentication for account recovery and management. <\/p>\n\n\n\n<p>The Ether.fi team credited security partners like Seal911, Doppel, <a href=\"https:\/\/coinscreed.com\/staging\/ethena-labs-halts-website-after-hack.html\" target=\"_blank\" data-type=\"post\" data-id=\"93781\" rel=\"noreferrer noopener\">Ethena<\/a>, and Distrust for their swift assistance during the attack.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">User Communication and Fund Safety<\/h2>\n\n\n\n<p>At 7:13 pm UTC on Sept. 24, Ether.fi advised its users via social media platform X not to <em>&#8220;click on any links&#8221;<\/em> or engage with their domain. They clarified that official updates would only come through X or Discord and not via email.<\/p>\n\n\n\n<p>After resolving the issue, Ether.fi reassured users that <em>&#8220;all funds are safe&#8221;<\/em> and that attackers had <em>&#8220;no opportunity&#8221;<\/em> to deploy any malicious DApps <em>&#8220;on any ether.fi-related domain.&#8221;<\/em><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ether.fi asserts security updates and partners for preventing a domain account takeover before user funds were taken. Ether.fi, a decentralized finance (DeFi) staking platform, reported that no user funds were compromised following a recent domain takeover attempt. On Sept. 24, the protocol experienced an attempted domain account hijacking through their registrar, Gandi.net. Fortunately, the attack [&hellip;]<\/p>\n","protected":false},"author":56,"featured_media":94729,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[3964,1996,197,128,937,11246],"class_list":["post-94714","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-cybersecurity","tag-decentralization","tag-defi","tag-ethereum","tag-hackers","tag-security"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/ETher.fi-Prevents-Domain-Account-Takeover-Secures-User-Funds-1.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/94714","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/56"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=94714"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/94714\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/94729"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=94714"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=94714"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=94714"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}