DeFi protocol Balancer suffers $240k loss in front end compromise spurred by DNS attack

1 year ago

Around $240,000 worthy of integer assets person been stolen done a frontend compromise of DeFi protocol Balancer, according to blockchain information steadfast Peckshield.

Earlier today, Balancer confirmed that its beforehand extremity was nether onslaught and urged users to debar interacting with the interface until further notice.

An update from the protocol’s DAO revealed that the compromise was caused by a Domain Name Service (DNS) attack. It wrote:

The Balancer DAO is actively addressing the existent DNS onslaught and is moving with each applicable parties to guarantee the afloat betterment of the Balancer UI. In the meantime, delight DO NOT interact with balancer.fi oregon app.balancer.fi until further notice.”

CryptoSlate effort to scope the website showed that MetaMask has flagged it arsenic a “potentially deceptive” site.

BalancerSource: Balancer Website

On-chain sleuth ZachXBT corroborated the stolen amount, sharing an representation of the attacker’s address.

The address identified by ZachXBT came to beingness astir 10 hours ago, and definite transactions associated with it person been tagged arsenic “scams.” Additionally, the wallet’s equilibrium presently contains $152,000 worthy of assets.

One Balancer user, Defi_Hanzo, explained however the onslaught occurred connected the website. Hanzo stated:

Website spams with “Switch to BSC/ETH/Avalanche”, you switch, past immoderate transaction popular up, you corroborate it by mishap (because u r connected balancer and what tin spell wrong) and boom, wealth gone”

However, Balancer has maintained that its astute declaration remains unaffected by the compromise. 

Meanwhile, the onslaught comes little than a period aft the DeFi task mislaid astir $1 cardinal worthy of assets to a compromise of its V2 pools. At the time, the task advised its users to retreat their funds from the affected pools to forestall further attacks.

The station DeFi protocol Balancer suffers $240k nonaccomplishment successful beforehand extremity compromise spurred by DNS attack appeared archetypal connected CryptoSlate.

View source