Curve Finance moves to new domain after DNS attack exposes security risks
By: cryptoslate|2025/05/14 08:30:07
0
Share
Curve Finance is moving permanently to a new web domain following a targeted DNS attack that exposed users to phishing risks.On May 13, the DeFi protocol confirmed that it will operate on Curve.finance, replacing the compromised Curve.fi.The protocol explained that it was making the move because of the prolonged downtime and limited support from .fi domain registrars.It stated:“[The] .fi [domain] will be down for too long / no point of moving back. Also registrars who can hold .fi are somewhat not as great as those who can deal with .finance.”On May 12, hackers hijacked the DNS records for Curve.fi, redirecting visitors to a malicious website that mimicked the protocol’s interface. This fake site attempted to trick users into signing wallet-draining transactions.Following the incident, Curve said that the issue was contained at the DNS level and that no internal systems were breached.However, the compromised website was left on for several hours as the domain registrar, iwantmyname, failed to respond to community complaints.Curve said:“[The registrar’s] response time is totally unacceptable: we need access to curve [.] fi taken away from hackers and the incident to be investigated.”Speaking on this, Yu Xian, the founder of blockchain security firm Slowmist, highlighted the risk that the issue could have caused, noting that:“The phishing gang [was] playing dirty tricks at the front end with fake wallet pop-up scams, directly fishing for mnemonic phrases... I have to say, this is pretty sleazy.”The compromised domain name has been frozen since the attack.Curve’s security challengesIn 2022, the protocol suffered a similar DNS hijack, which led to user losses totaling approximately $530,000. Notably, the firm was using the same registrar, iwantmyname, at the time of the attack.Meanwhile, the recent DNS attack comes just over a week after a separate security event in which a hacker temporarily took over Curve’s X account.On May 5, a hacker took over the platform’s social media handle to post phishing links. The team regained control of the account quickly and said no user funds were impacted.Meanwhile, security experts emphasized that the back-to-back incidents show that attackers are shifting focus from code exploits to infrastructure-based vulnerabilities.This year, the crypto industry has lost around $2 billion to malicious actors who have exploited centralized exchanges like Bybit and several DeFi protocols.The post Curve Finance moves to new domain after DNS attack exposes security risks appeared first on CryptoSlate.
You may also like

Atkins Marks One-Year Anniversary at SEC: Crypto Regulation Shifts from ‘Enforcement Heavy’ to ‘Rulemaking Mode’
Before the bill is passed, the SEC's cryptocurrency regulatory framework remains in a transition state of "administrative guidance + enforcement actions."

Under Political Pressure, Is the Federal Reserve Still Independent?
Powell believes that political pressure is not a threat, and what truly determines the Fed's independence is the Fed itself.

Yellen's Past Remarks: How Will This Incoming "Fed Chair" Disrupt the Federal Reserve? Janet Yellen, who is expected to become the next Chair of the Federal Reserve, has made several significant statements in the past regarding monetary policy, financ...
Powell's reform blueprint not only looks bold and ambitious, but also directly targets many vulnerabilities of the Federal Reserve. Facing the upcoming Senate confirmation hearing, how will this Fed's presumptive new "helmsman" reshape the future of the world's largest central bank?

ZachXBT vs. RAVE: Is a “Clean” Market Really What Speculators Want?
While cleaning up manipulation, it may also involve cleaning up liquidity

Arbitrum Poses as Hacker, 'Steals' Back Money Lost by KelpDAO
Even though Arbitrum wielded the admin key, the battle is far from over.

Without Cook's Apple, Can it Still Grow in the AI Era?
The iPhone Remains at its Peak, But Apple is at a Turning Point

Saylor's Bitcoin Holdings Surpass BlackRock, How Does This "Bitcoin Financing Machine" STRC Work?
Funding Cap is not equal to Execution Path; whether Bitcoin can cooperate is the true variable.

What Is RWA? What Is RWA in Crypto (Complete 2026 Guide)
Wondering what is RWA in crypto? We explain what RWA is, break down RWA tokenization in simple no-jargon terms, and cover why it's 2026's hottest crypto narrative.

What Is the KelpDAO Attack? What It Means for Aave Users in 2026
KelpDAO suffered a $292M rsETH exploit on April 18, 2026, triggering Aave market freezes and $13B DeFi outflows. Here’s what happened, whether Aave is safe now, and what users should do next.

Is your gold really "within reach"? The geographical blind spots of custodial services behind tokenized gold
When "complete physical support" does not equal "truly desirable," the risks are just beginning to emerge.

Cook Passes the Baton, Anthropic Gears Up | Rewire News Morning Brief
In the window of AI reshaping the hardware landscape, Apple has chosen a Maker

Will the Fed Cut Interest Rates Again? Tonight's Data Is Key
Citi believes geopolitical turbulence is temporary and the rate cut trajectory remains unchanged. Meanwhile, Deutsche Bank warns that the policy has reached a neutral stance, with no interest rate cuts in the foreseeable future.

The person taking over Apple has to do something he has never done before
Software, AI, services—areas he never directly controlled in his 25-year Apple career

Why Are You Always Losing Money on Polymarket? Because You're Betting on News, While The Rulebook Favors Insiders
At Polymarket, most people who bet incorrectly are not wrong in their prediction but rather in not having read the rules carefully.

Not a Price Hike, but a Supply Shortage? Oil Price Has Crossed the Threshold
A $95 Per Barrel Price Is Far From Enough to Rebalance the Oil Market

a16z: 5 Ways Blockchain Helps AI Agent Infrastructure
Artificial intelligence makes scaling cost-effective, but it is difficult to establish trust. Cryptocurrency can rebuild trust on a large scale.

Morning News | The Hong Kong Securities and Futures Commission announced the regulatory framework for secondary market trading of tokenized investment products; Strategy increased its holdings by 34,164 bitcoins last week; KAIO completed a strategic fi...
Overview of Important Market Events on April 20

What Is an XRP Wallet? The Best Wallets to Store XRP (2026 Updated)
An XRP wallet lets you safely store, send, and receive XRP on the XRP Ledger. Learn what wallets support XRP and discover the best XRP wallets for beginners and long-term holders in 2026.
Atkins Marks One-Year Anniversary at SEC: Crypto Regulation Shifts from ‘Enforcement Heavy’ to ‘Rulemaking Mode’
Before the bill is passed, the SEC's cryptocurrency regulatory framework remains in a transition state of "administrative guidance + enforcement actions."
Under Political Pressure, Is the Federal Reserve Still Independent?
Powell believes that political pressure is not a threat, and what truly determines the Fed's independence is the Fed itself.
Yellen's Past Remarks: How Will This Incoming "Fed Chair" Disrupt the Federal Reserve? Janet Yellen, who is expected to become the next Chair of the Federal Reserve, has made several significant statements in the past regarding monetary policy, financ...
Powell's reform blueprint not only looks bold and ambitious, but also directly targets many vulnerabilities of the Federal Reserve. Facing the upcoming Senate confirmation hearing, how will this Fed's presumptive new "helmsman" reshape the future of the world's largest central bank?
ZachXBT vs. RAVE: Is a “Clean” Market Really What Speculators Want?
While cleaning up manipulation, it may also involve cleaning up liquidity
Arbitrum Poses as Hacker, 'Steals' Back Money Lost by KelpDAO
Even though Arbitrum wielded the admin key, the battle is far from over.
Without Cook's Apple, Can it Still Grow in the AI Era?
The iPhone Remains at its Peak, But Apple is at a Turning Point

