{"id":248357,"date":"2024-07-27T02:58:01","date_gmt":"2024-07-27T02:58:01","guid":{"rendered":"https:\/\/michigandigitalnews.com\/index.php\/2024\/07\/27\/dydx-domain-faces-repeated-dns-hijacking-incidents\/"},"modified":"2025-06-25T17:13:48","modified_gmt":"2025-06-25T17:13:48","slug":"dydx-domain-faces-repeated-dns-hijacking-incidents","status":"publish","type":"post","link":"https:\/\/michigandigitalnews.com\/index.php\/2024\/07\/27\/dydx-domain-faces-repeated-dns-hijacking-incidents\/","title":{"rendered":"dYdX Domain Faces Repeated DNS Hijacking Incidents"},"content":{"rendered":"<p> [ad_1]<br \/>\n<\/p>\n<div>\n<figure class=\"figure mt-2\">&#13;<br \/>\n                                &#13;<\/p>\n<p>&#13;<br \/>\n                                    <a href=\"https:\/\/blockchain.news\/Profile\/Rongchai-Wang\">Rongchai Wang<\/a>&#13;<br \/>\n                                    <span class=\"publication-date ml-2\"> Jul 26, 2024 03:41<\/span>&#13;\n                                <\/p>\n<p>&#13;<\/p>\n<p class=\"lead\">dYdX&#8217;s domain suffered multiple DNS hijacking attacks due to vulnerabilities in Squarespace&#8217;s OAuth and account recovery protocols, highlighting broader security concerns.<\/p>\n<p>&#13;<br \/>\n                                <a href=\"https:\/\/image.blockchain.news:443\/features\/7730C0965ED8395C793CC10166A96E60F5D0DB4492875EEADCDF2E77E9F203FB.jpg\">&#13;<br \/>\n                                    <img decoding=\"async\" class=\"rounded\" src=\"https:\/\/image.blockchain.news:443\/features\/7730C0965ED8395C793CC10166A96E60F5D0DB4492875EEADCDF2E77E9F203FB.jpg\" alt=\"dYdX Domain Faces Repeated DNS Hijacking Incidents\"\/>&#13;<br \/>\n                                <\/a>&#13;<br \/>\n                            <\/figure>\n<p>dYdX, a prominent decentralized trading platform, recently faced multiple DNS hijacking incidents impacting its domain <a rel=\"nofollow\" href=\"http:\/\/dydx.exchange\">dydx.exchange<\/a>. These attacks have raised significant concerns about the security protocols of domain registrars and the broader implications for the crypto industry.<\/p>\n<h2>Background<\/h2>\n<p>In 2023, Squarespace acquired the rights to all domains from the now-defunct Google Domains, migrating them over several months. The <a rel=\"nofollow\" href=\"http:\/\/dydx.exchange\">dydx.exchange<\/a> domain was transferred on June 15, 2024. However, on July 9, attackers managed to gain access to this domain, changing its DNS Nameservers from Cloudflare to DDoS-Guard. The attack was mitigated by DNSSEC settings, which blocked unauthorized access.<\/p>\n<h2>OAuth Weakness Exploited<\/h2>\n<p>Following the initial incident, dYdX worked with Squarespace to restore access and rotated all security credentials. Despite these measures, similar attacks were reported on other crypto-specific domains migrated from Google Domains to Squarespace. SEAL, a crypto security team, initiated an investigation, revealing potential technical vulnerabilities within Squarespace.<\/p>\n<p>On July 18, Squarespace confirmed an exploited security issue with OAuth logins, which was fixed by July 12. Despite this, dYdX decided to change domain registrars, though they believed Squarespace had addressed the vulnerability.<\/p>\n<h2>Account-Recovery Attack<\/h2>\n<p>On July 23, the <a rel=\"nofollow\" href=\"http:\/\/dydx.exchange\">dydx.exchange<\/a> domain was compromised again. Attackers changed the DNS Nameservers and removed DNSSEC settings, hosting a malicious site to steal funds from connected wallets. dYdX collaborated with SEAL and wallet providers like Metamask and Phantom to block the malicious site. Approximately $31,000 was lost by two users during this period.<\/p>\n<p>Upon recovery, it was discovered that the attacker had used a social-engineering attack to reset the domain admin email to their own, bypassing 2FA due to Squarespace\u2019s account-recovery process. Squarespace customer service had reset the account without reaching out to other listed admins.<\/p>\n<h2>Securing the Domain<\/h2>\n<p>As a response to these incidents, dYdX transferred the domain registration to Cloudflare on July 24, completing the process in six hours. No security issues with dYdX\u2019s smart contracts, backend systems, or the dYdX Chain were found as a result of these incidents.<\/p>\n<h2>Industry Implications<\/h2>\n<p>These incidents underscore the importance of robust security measures for domain registrars, especially for crypto-related domains. The vulnerabilities in Squarespace\u2019s OAuth and account-recovery protocols highlight the need for continuous improvement in security practices to prevent such attacks.<\/p>\n<h2>About dYdX<\/h2>\n<p>dYdX aims to democratize access to financial opportunities, with the dYdX Chain representing a significant step forward in this mission. For more information, visit <a rel=\"nofollow\" href=\"https:\/\/dydx.exchange\">dydx.exchange<\/a>.<\/p>\n<p><span><i>Image source: Shutterstock<\/i><\/span><\/p>\n<p>                            <!-- Divider --><\/p>\n<p>                            <!-- Author info END --><br \/>\n                            <!-- Divider --><\/p><\/div>\n<p>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/blockchain.news\/news\/dydx-domain-faces-repeated-dns-hijacking-incidents\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[ad_1] &#13; &#13; &#13; Rongchai Wang&#13; Jul 26, 2024 03:41&#13; &#13; dYdX&#8217;s domain suffered multiple DNS hijacking attacks due to vulnerabilities in Squarespace&#8217;s OAuth and<\/p>\n","protected":false},"author":1,"featured_media":248358,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[171],"tags":[],"_links":{"self":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/posts\/248357"}],"collection":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/comments?post=248357"}],"version-history":[{"count":0,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/posts\/248357\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/media\/248358"}],"wp:attachment":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/media?parent=248357"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/categories?post=248357"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/tags?post=248357"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}