CertiK Names the Reason for DNS Hijacking on DeFi

0

Millions of digital assets have been stolen by cyber adversaries via DNS hijacking attacks for phishing purposes, targeting users’ wallet seed phrases, or creating deceptive webpages that closely resemble legitimate sites.

Attacks on Domain Name Systems (DNSs) play a crucial role in the internet’s infrastructure, providing insights into security incidents in Web 2 that have directly affected the Web3 industry. However, transitioning to decentralized frontends has emerged as a practical way to tackle these challenges, according to a recent report by CertiK.

DNS Hijacking of DeFi Protocols

DNS hijacking is an attack that targets a core component of Internet infrastructure. It has the potential to render a public DNS service inaccessible in certain scenarios, or it can be employed to reroute users to malicious websites, in other cases.

Typically, the attacker manipulates the DNS by substituting the mapping (DomainName, Legitimate IP) with (DomainName, MaliciousServer IP). This tampering enables them to intercept future users’ DNS queries, directing them to fraudulent websites without the users’ awareness, CertiK explained.

Users inadvertently access these deceitful sites via the compromised servers, exposing themselves to potential phishing attacks and the downloading of malware that can compromise their devices.

CreamFinance and PancakeSwap reported DNS hijacking attacks in 2021, two public RPC gateways offered by Ankr for Polygon and Fantom wallets were compromised via a DNS hijacking attack the following year. During the same period, Cronos-based DEX MM.Finance, Curve Finance, Celer Protocol, Fantom-based SpiritSwap, and Polygon-based QuickSwap also reported frontend breaches as a result of a DNS hijack attack.

These incidents essentially highlighted the significant impact of vulnerabilities in Web2 on the Web3 ecosystem due to the interconnected security of these two domains.

CertiK said that the persistent challenge of DNS credential theft and highlighted vulnerabilities arising from third-party domain service providers pose a significant challenge to Web3 projects. The core Web3 protocols themselves were not inherently flawed; rather, it was the traditional centralized domain infrastructure that left them susceptible to these issues.

Solution

CertiK emphasized the need for adopting the combination of IPFS and ENS which demonstrates the potential of decentralized and DLT-based solutions in reducing DNS hijacking attacks. These systems prioritize content authenticity, minimize points of failure, and substantially lower the vulnerabilities associated with centralized control and authority.

“The move towards decentralized infrastructure, along with continuous strengthening of both human and technological defenses, has become essential for the future security of Web3 projects and their users.”

SPECIAL OFFER (Sponsored)
Binance Free $100 (Exclusive): Use this link to register and receive $100 free and 10% off fees on Binance Futures first month (terms).

PrimeXBT Special Offer: Use this link to register & enter CRYPTOPOTATO50 code to receive up to $7,000 on your deposits.

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 26,238.03
ethereum
Ethereum (ETH) $ 1,591.56
tether
Tether (USDT) $ 0.999602
bnb
BNB (BNB) $ 212.55
xrp
XRP (XRP) $ 0.497697
usd-coin
USDC (USDC) $ 1.00
staked-ether
Lido Staked Ether (STETH) $ 1,591.13
cardano
Cardano (ADA) $ 0.244451
dogecoin
Dogecoin (DOGE) $ 0.060525
solana
Solana (SOL) $ 18.92
tron
TRON (TRX) $ 0.084936
the-open-network
Toncoin (TON) $ 2.10
polkadot
Polkadot (DOT) $ 4.00
matic-network
Polygon (MATIC) $ 0.506923
litecoin
Litecoin (LTC) $ 63.87
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 26,213.02
shiba-inu
Shiba Inu (SHIB) $ 0.000007
bitcoin-cash
Bitcoin Cash (BCH) $ 214.86
chainlink
Chainlink (LINK) $ 7.37
dai
Dai (DAI) $ 0.999659
true-usd
TrueUSD (TUSD) $ 0.998110
leo-token
LEO Token (LEO) $ 3.66
uniswap
Uniswap (UNI) $ 4.29
avalanche-2
Avalanche (AVAX) $ 8.99
stellar
Stellar (XLM) $ 0.112424
monero
Monero (XMR) $ 144.59
okb
OKB (OKB) $ 42.91
binance-usd
BUSD (BUSD) $ 1.00
ethereum-classic
Ethereum Classic (ETC) $ 15.09
cosmos
Cosmos Hub (ATOM) $ 6.95
hedera-hashgraph
Hedera (HBAR) $ 0.049395
filecoin
Filecoin (FIL) $ 3.19
internet-computer
Internet Computer (ICP) $ 2.95
crypto-com-chain
Cronos (CRO) $ 0.049887
lido-dao
Lido DAO (LDO) $ 1.46
maker
Maker (MKR) $ 1,419.66
quant-network
Quant (QNT) $ 86.61
mantle
Mantle (MNT) $ 0.388425
aptos
Aptos (APT) $ 5.24
vechain
VeChain (VET) $ 0.016470
arbitrum
Arbitrum (ARB) $ 0.823523
optimism
Optimism (OP) $ 1.28
near
NEAR Protocol (NEAR) $ 1.08
kaspa
Kaspa (KAS) $ 0.046828
rocket-pool-eth
Rocket Pool ETH (RETH) $ 1,728.25
aave
Aave (AAVE) $ 60.72
the-graph
The Graph (GRT) $ 0.086385
whitebit
WhiteBIT Coin (WBT) $ 5.24
algorand
Algorand (ALGO) $ 0.094961
usdd
USDD (USDD) $ 0.997606