<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Compound_Finance_Official_Website_DNS_Hijacking</id>
	<title>Compound Finance Official Website DNS Hijacking - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Compound_Finance_Official_Website_DNS_Hijacking"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Compound_Finance_Official_Website_DNS_Hijacking&amp;action=history"/>
	<updated>2026-05-01T09:05:31Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Compound_Finance_Official_Website_DNS_Hijacking&amp;diff=6116&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/compoundfinanceofficialwebsitednshijacking.php}} {{Unattributed Sources}}  Compound Finance LogoCompound Finance is one of the most popular decentralized finance protocols for loans. They used SquareSpace as their domain registrar. Early in the morning of July 11th, their domain was hijacked, and pointed users to a malicious wallet draining application....&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Compound_Finance_Official_Website_DNS_Hijacking&amp;diff=6116&amp;oldid=prev"/>
		<updated>2024-09-18T21:57:26Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/compoundfinanceofficialwebsitednshijacking.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Compoundfinance.jpg&quot; title=&quot;File:Compoundfinance.jpg&quot;&gt;thumb|Compound Finance Logo&lt;/a&gt;Compound Finance is one of the most popular decentralized finance protocols for loans. They used SquareSpace as their domain registrar. Early in the morning of July 11th, their domain was hijacked, and pointed users to a malicious wallet draining application....&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/compoundfinanceofficialwebsitednshijacking.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Compoundfinance.jpg|thumb|Compound Finance Logo]]Compound Finance is one of the most popular decentralized finance protocols for loans. They used SquareSpace as their domain registrar. Early in the morning of July 11th, their domain was hijacked, and pointed users to a malicious wallet draining application. They are among a few domains hosted on SquareSpace which were hijacked. It is unclear how many users were drained from this attack.&amp;lt;ref name=&amp;quot;slowmisthackedarchive-14638&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;lewellenmichaeltwitter-14698&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;compoundfinancetwitter-14699&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;mayhalltwitter-14700&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;blockaidtwitter-14701&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;thepulsewallettwitter-14702&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;0xngmitwitter-14703&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;dankazenofftwitter-14704&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;mwctwitter-14705&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;protos-14706&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;pelehsergiitwitter-14707&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;mlionaitwitter-14708&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;thebloktalktwitter-14709&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;ankitavtwitter-14710&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;quadrigainitiative-14711&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About Compound Finance ==&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Compound Finance is one of the most widely used protocols in the DeFi ecosystem. Deployed on Ethereum, its purpose is to issue automatic, permissionless loans of Ether and various ERC20 tokens. As of February 2022, the protocol held more than $10 billion in assets across 18 markets.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;To invest in Compound, users deposit Ether or supported ERC20 tokens into one of the protocol’s markets. In exchange, they receive cTokens for that market, with which they can redeem their investment. Compound’s cTokens are differentiated and denominated according to the underlying asset. For example, investors who deposit Ether (ETH) receive cETH tokens, which are redeemable for ETH. Similarly, investors who deposit USDC receive cUSDC tokens, which are redeemable for USDC, and so on. In addition to being redeemable for the underlying asset, cTokens can be traded according to their market value.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The total value of each market increases as funds are lent out and repaid. As the value held in a market grows, the cTokens for that market increase in value and can be redeemed for more of the underlying asset. In this way, investors accrue interest. When the protocol operates as intended, the value of a cToken relative to its underlying asset should only increase, i.e., only positive interest rates should be possible.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
This sections is included if a case involved deception or information that was unknown at the time. Examples include:&lt;br /&gt;
&lt;br /&gt;
* When the service was actually started (if different than the &amp;quot;official story&amp;quot;).&lt;br /&gt;
* Who actually ran a service and their own personal history.&lt;br /&gt;
* How the service was structured behind the scenes. (For example, there was no &amp;quot;trading bot&amp;quot;.)&lt;br /&gt;
* Details of what audits reported and how vulnerabilities were missed during auditing.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - Compound Finance Official Website DNS Hijacking&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|July 11th, 2024 12:49:00 AM MDT&lt;br /&gt;
|ZachXBT Reporting&lt;br /&gt;
|ZachXBT tweets to announce that the Compound Finance website appears to be redirecting to another malicious phishing site.&lt;br /&gt;
|-&lt;br /&gt;
|July 11th, 2024 12:50:00 AM MDT&lt;br /&gt;
|Tweet Report&lt;br /&gt;
|A tweet reports that the Compound Finance website is redirecting to a phishing website compound-finance.app.&lt;br /&gt;
|-&lt;br /&gt;
|July 11th, 2024 1:37:00 AM MDT&lt;br /&gt;
|Michael Lewellen Tweet&lt;br /&gt;
|Michael Lewellen tweets to notify that the Compound Finance website appears to be hijacked and is currently hosting a phishing site.&lt;br /&gt;
|-&lt;br /&gt;
|July 11th, 2024 3:15:00 AM MDT&lt;br /&gt;
|Compound Labs Tweet&lt;br /&gt;
|Compound Labs reports that their domain is hijacked and they will be providing an update.&lt;br /&gt;
|-&lt;br /&gt;
|July 11th, 2024 5:35:00 AM MDT&lt;br /&gt;
|CoinDesk Article&lt;br /&gt;
|CoinDesk publishes an article on both domain hijackings.&lt;br /&gt;
|-&lt;br /&gt;
|July 11th, 2024 9:32:00 AM MDT&lt;br /&gt;
|BlockAid Tweet/Analysis&lt;br /&gt;
|BlockAid tweets to notify about the developing situation. They report that both Compound Finance and Celer Network are found to be hijacked. The sites are traced to use the Inferno Drainer malware.&lt;br /&gt;
|-&lt;br /&gt;
|July 11th, 2024 11:00:00 AM MDT&lt;br /&gt;
|SquareSpace Security Breaches&lt;br /&gt;
|Reportedly, multiple websites are targeted.&lt;br /&gt;
|-&lt;br /&gt;
|July 13th, 2024 5:28:00 AM MDT&lt;br /&gt;
|BlokTalk Tweet&lt;br /&gt;
|BlokTalk reports on the potential breach of the Pendle Finance website.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited?&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
The total amount lost is unknown.&lt;br /&gt;
&lt;br /&gt;
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
&amp;quot;Compound DAO security advisor Michael Lewellen tweeted that the Compound Finance official website (http://compound.finance) has been compromised and is currently hosting a phishing site. Do not interact with the site until further notice.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;ALERT: The http://compound.finance URL has been compromised and is currently hosting a phishing site. DO NOT interact with the http://compound.finance website until further notice.&lt;br /&gt;
&lt;br /&gt;
The Compound protocol itself is not impacted and all smart contract funds are safe.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;URGENT: The Compound Labs website (compound[.]finance) has been compromised. &lt;br /&gt;
&lt;br /&gt;
Please do not visit the website or clink any links until further notice. An update will be provided when available.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;BREAKING: Multiple cryptocurrency platforms tied to Squarespace, including Compound Finance and Celer Network, reported security breaches affecting their websites. &lt;br /&gt;
&lt;br /&gt;
The breach appears to be a DNS attack, adding to the long list of crypto hacks so far in 2024.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Security advisor to the Compound DAO, Michael Lewellen, posted a community alert via X (formerly Twitter), urging users to avoid the platform’s website. Compound Finance confirmed the attack 90 minutes later. The breach was highlighted earlier by ZachXBT via Telegram.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
The total amount recovered is unknown.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;slowmisthackedarchive-14638&amp;quot;&amp;gt;[https://web.archive.org/web/20240711160134/https://hacked.slowmist.io/ SlowMist Hacked - SlowMist Zone] (Accessed Jul 11, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;lewellenmichaeltwitter-14698&amp;quot;&amp;gt;[https://twitter.com/LewellenMichael/status/1811303839888261530 @LewellenMichael Twitter] (Accessed Jul 15, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;compoundfinancetwitter-14699&amp;quot;&amp;gt;[https://twitter.com/compoundfinance/status/1811328333063520683 @compoundfinance Twitter] (Accessed Jul 15, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;mayhalltwitter-14700&amp;quot;&amp;gt;[https://twitter.com/Mayhall_/status/1811291962768871569 @Mayhall_ Twitter] (Accessed Jul 15, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;blockaidtwitter-14701&amp;quot;&amp;gt;[https://twitter.com/blockaid_/status/1811423288763318307 @blockaid_ Twitter] (Accessed Jul 15, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;thepulsewallettwitter-14702&amp;quot;&amp;gt;[https://twitter.com/ThePulseWallet/status/1811291724637245561 @ThePulseWallet Twitter] (Accessed Jul 15, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;0xngmitwitter-14703&amp;quot;&amp;gt;[https://twitter.com/0xngmi/status/1811376786799784348 @0xngmi Twitter] (Accessed Jul 15, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;dankazenofftwitter-14704&amp;quot;&amp;gt;[https://twitter.com/DanKazenoff/status/1811422512359874593 @DanKazenoff Twitter] (Accessed Jul 15, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;mwctwitter-14705&amp;quot;&amp;gt;[https://twitter.com/_mwc/status/1811432212824481970 @_mwc Twitter] (Accessed Jul 15, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;protos-14706&amp;quot;&amp;gt;[https://protos.com/compound-finance-and-celer-network-websites-compromised-in-front-end-attacks/ Compound Finance and Celer Network websites compromised in ‘front-end’ attacks] (Accessed Jul 15, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;pelehsergiitwitter-14707&amp;quot;&amp;gt;[https://twitter.com/PelehSergii/status/1811430583739772938 @PelehSergii Twitter] (Accessed Jul 15, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;mlionaitwitter-14708&amp;quot;&amp;gt;[https://twitter.com/MLion_AI/status/1811580481110180071 @MLion_AI Twitter] (Accessed Jul 15, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;thebloktalktwitter-14709&amp;quot;&amp;gt;[https://twitter.com/TheBlokTalk/status/1812086819468743042 @TheBlokTalk Twitter] (Accessed Jul 15, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;ankitavtwitter-14710&amp;quot;&amp;gt;[https://twitter.com/ankitav/status/1811445433191006235 @ankitav Twitter] (Accessed Jul 15, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;quadrigainitiative-14711&amp;quot;&amp;gt;[https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Compound_Finance_Live_Critical_Vulnerability Compound Finance Live Critical Vulnerability - Quadriga Initiative Cryptocurrency Hacks, Scams, and Frauds Repository] (Accessed Jul 15, 2024)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>