Cointime

Download App
iOS & Android

Hackers impersonated eth.limo team to hijack its domain: Post-mortem

Ethereum Name Service gateway eth.limo has revealed that the domain hijacking on Friday was caused by a social engineering attack directed against EasyDNS, its domain name service provider. 

According to a postmortem published by eth.limo on Saturday, an attacker impersonated one of its team members to initiate an account recovery process with easyDNS, granting access to the eth.limo account and allowing them to alter domain settings.

“The NS records were changed and directed to Cloudflare… Once we understood that a DNS hijack had taken place, we immediately notified the community as well as Vitalik Buterin and others. We then began contacting EasyDNS in an attempt to respond to the incident,” the company said.

Eth.limo serves as a Web2 bridge, providing access to around 2 million decentralized websites using the .eth domain name. Hijacking the service could allow an attacker to redirect users to malicious websites. Ethereum co-founder Vitalik Buterin warned users Friday to avoid his blog until the incident was resolved.

Mark Jeftovic, CEO of easyDNS, has publicly accepted responsibility for the incident in its own postmortem report. 

“We screwed up and we own it,” said Jeftovic on Saturday. 

“This would mark the first successful social engineering attack against an easyDNS client in our 28-year history. There have been countless attempts.”  

Both companies have pointed to the Domain Name System Security Extension (DNSSEC) in thwarting the hacker’s attempts to do further damage. 

The attacker couldn’t produce valid cryptographic signatures, so Domain Name System resolvers rejected the attacker’s forged DNS responses, causing users to see error messages instead of being redirected to malicious sites. 

“DNSSEC was enabled for their domain when the attackers attempted to flip their nameservers, presumably to effect some manner of phishing or malware injection attack, DNSSEC-aware resolvers, which most are these days, began dropping queries,” Jeftovic said. 

  Source: eth.limo


In its postmortem, eth.limo noted that because the attacker lacked the signing keys, they were unable to bypass the safeguards, which likely “reduced the blast radius of the hijack. We are not aware of any user impact at this time. We will provide updates if that changes.”

easyDNS makes changes since the attack

Jeftovic described the social engineering attack as “highly sophisticated,” and said easyDNS is still conducting a post-mortem on how the breach occurred, and has already begun rolling out changes to prevent a recurrence.

  Source: easyDNS


“In eth.limo’s case, we will be migrating them to Domainsure, which has a security posture more suited toward enterprise and high-value fintech domains, TLDR there is no mechanism for an account recovery on Domainsure, it’s not a thing,” he added.

“On behalf of everyone here, I apologize to the eth.limo team and the wider Ethereum community. ENS has always had a special place in our heart as the first registrar to enable ENS linking to web2 domains and we’ve been involved in the space since 2017.”

The eth.limo incident is the latest in a series of domain hijackings targeting crypto projects. Days earlier, decentralized exchange aggregator CoW Swap lost control of its website after an unknown party hijacked its domain. 

Steakhouse Financial, a DeFi advisory and research firm, similarly disclosed at the end of March that it had lost control of its domain to an attacker.

Comments

All Comments

Recommended for you

  • ZEC Surpasses $400

    Market data shows that ZEC has surpassed $400, currently priced at $405.93, with a 24-hour increase of 9.65%. The market is experiencing significant volatility, so please ensure proper risk management.

  • BTC Briefly Surpasses $62,000

    Market data shows that BTC briefly surpassed $62,000, currently priced at $61,780.01, with a 24-hour increase of 1.65%. The market is experiencing significant volatility, so please ensure proper risk management.

  • OpenAI Plans Major Upgrade for ChatGPT to Generate More Revenue

    On June 7, according to the Financial Times, OpenAI is preparing for the largest upgrade of ChatGPT since its launch. The $850 billion company is looking for new growth engines ahead of its planned IPO this year. The company intends to transform the chatbot into a 'super app' by integrating programming tools with AI, adding several new products that executives believe will generate higher revenue. According to more than a dozen current and former employees, these adjustments are part of OpenAI's overall restructuring plan. OpenAI is reallocating resources to aggressively pursue high-profit enterprise clients and is gearing up for intensified competition with rival Anthropic. This adjustment will elevate the status of OpenAI's programming product Codex and increase resource investment, reflecting a growing consensus within the company that the future of AI is not just chatbots that answer questions, but intelligent agents that can perform tasks for users.

  • BTC Surges Past $61,000

    Market data shows that BTC has surged past $61,000, currently priced at $61,039.53, with the 24-hour decline narrowing to 0.53%. The market is experiencing significant volatility, so please ensure proper risk management.

  • CSRC Chairman Wu Qing: Fund Industry's Stock Investment Grows 41% to 13.4 Trillion Yuan

    On June 6, the China Securities Regulatory Commission (CSRC) released Wu Qing's speech at the Fourth Member Representative Conference of the China Securities Investment Fund Industry Association. Wu Qing pointed out that over the past five years, the scale of stock investments in the fund industry has grown by 41%, reaching 13.4 trillion yuan, with the proportion of A-share circulating market value held reaching 13.7%. Rational investment, value investment, and long-term investment have become widely accepted concepts. At the same time, the fund industry has become an important partner for medium- and long-term funds such as social security, insurance, and annuities, and a key trustee for equity investments, playing a crucial role in optimizing the investor structure of the capital market, broadening the channels for medium- and long-term funds to enter the market, increasing market liquidity, and reducing irrational market fluctuations.

  • BTC Falls Below $61,000

    Market data shows that BTC has fallen below $61,000, currently priced at $60,996, with a 24-hour decline of 1.15%. The market is experiencing significant volatility, so please ensure proper risk management.

  • BTC Surpasses $61,000

    Market data shows that BTC has surpassed $61,000, currently priced at $61,005.65, with a 24-hour decline of 3.74%. The market is experiencing significant volatility, so please ensure proper risk management.

  • USDT Surpasses ETH to Become the Second Largest Cryptocurrency by Market Cap

    On June 6, market data showed that USDT's market capitalization surpassed that of ETH, making it the second largest cryptocurrency by market cap. As of now, USDT's market cap stands at $187.034 billion, while ETH's market cap is $184.423 billion.

  • BTC Falls Below $60,000

    Market data shows that BTC has fallen below $60,000, currently priced at $59,995.63, with a 24-hour decline of 4.36%. The market is experiencing significant volatility, so please ensure proper risk management.