<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=DYdX_Exchange_DNS_Hijacking_Attack</id>
	<title>DYdX Exchange DNS Hijacking Attack - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=DYdX_Exchange_DNS_Hijacking_Attack"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=DYdX_Exchange_DNS_Hijacking_Attack&amp;action=history"/>
	<updated>2026-04-22T21:02:50Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=DYdX_Exchange_DNS_Hijacking_Attack&amp;diff=6298&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/dydxexchangednshijackingattack.php}} {{Unattributed Sources}}  dYdX Logo/Homepage&lt;ref name=&quot;slowmisthackedarchive-15180&quot; /&gt;&lt;ref name=&quot;dydx-15181&quot; /&gt;&lt;ref name=&quot;dydx-15182&quot; /&gt;&lt;ref name=&quot;llamaonthebrinktwitter-15183&quot; /&gt;&lt;ref name=&quot;open4profittwitter-15184&quot; /&gt;&lt;ref name=&quot;lawrencechiu14twitter-15185&quot; /&gt;&lt;ref name=&quot;dydxtwitter-15186&quot; /&gt;&lt;ref name=&quot;dydxtwitter-15187&quot; /&gt;&lt;ref...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=DYdX_Exchange_DNS_Hijacking_Attack&amp;diff=6298&amp;oldid=prev"/>
		<updated>2024-10-25T20:04:43Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/dydxexchangednshijackingattack.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Dydx.jpg&quot; title=&quot;File:Dydx.jpg&quot;&gt;thumb|dYdX Logo/Homepage&lt;/a&gt;&amp;lt;ref name=&amp;quot;slowmisthackedarchive-15180&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;dydx-15181&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;dydx-15182&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;llamaonthebrinktwitter-15183&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;open4profittwitter-15184&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;lawrencechiu14twitter-15185&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;dydxtwitter-15186&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;dydxtwitter-15187&amp;quot; /&amp;gt;&amp;lt;ref...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/dydxexchangednshijackingattack.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Dydx.jpg|thumb|dYdX Logo/Homepage]]&amp;lt;ref name=&amp;quot;slowmisthackedarchive-15180&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;dydx-15181&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;dydx-15182&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;llamaonthebrinktwitter-15183&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;open4profittwitter-15184&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;lawrencechiu14twitter-15185&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;dydxtwitter-15186&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;dydxtwitter-15187&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;wazzupcryptotwitter-15188&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;derektmckinneytwitter-15189&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;techflowposttwitter-15190&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;dydxtwitter-15191&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;dydxtwitter-15192&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;dydxtwitter-15193&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;dydxtwitter-15194&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;dydxtwitter-15195&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;goplussecwarextwitter-15196&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;echoewebtwitter-15197&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;parrotcoinstwitter-15198&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;veritasweb3twitter-15199&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About dYdX Exchange ==&lt;br /&gt;
&amp;quot;Perpetuals, decentralized.&amp;quot; &amp;quot;Trade Perpetual Contracts with low fees, deep liquidity, and up to 25× more Buying Power. Deposit just $10 to get started.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;We built the fastest and most powerful decentralized exchange ever.&amp;quot; &amp;quot;Once you deposit to Layer 2, you will no longer pay fees to miners for each transaction.&amp;quot; &amp;quot;Trades are executed instantly and confirmed on the blockchain within hours.&amp;quot; &amp;quot;Unlike other platforms, there is no wait required to withdraw your funds from Layer 2.&amp;quot; &amp;quot;We've redesigned our exchange from the ground up, so you can use it from any device.&amp;quot; &amp;quot;StarkWare's Layer 2 solution provides increased security &amp;amp; privacy via zero-knowledge rollups.&amp;quot; &amp;quot;Access leverage across positions in multiple markets from a single account.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;dYdX is the leading DeFi protocol developer for advanced trading. Trade 135 cryptocurrencies with low fees, deep liquidity, and up to 20× buying power.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
&amp;quot;In 2023, Squarespace acquired the rights to all domains from the now-defunct Google Domains. All domains were migrated over a period of months. The domain dydx.exchange, owned by dYdX Trading, was migrated from Google Domains to Squarespace on June 15, 2024.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;On July 9, while registered with Squarespace, attackers gained access to the dydx.exchange domain, and modified the the DNS Nameservers from Cloudflare to DDoS-Guard. This attack was mitigated by DNSSEC settings that remained set on the registrar. This resulted in would-be-visitors’ browsers failing to authenticate the DNS changes, and correctly blocking users from viewing the page.&lt;br /&gt;
&lt;br /&gt;
dYdX promptly contacted Squarespace customer service during this incident and they restored access to the account quickly according to their account-recovery policies. dYdX ensured that all passwords and 2FA were rotated on Squarespace accounts and that the attacker’s access was fully removed. The attack was completely mitigated and fixed within a couple of hours.&lt;br /&gt;
&lt;br /&gt;
Two days later on July 11, several additional reports of targeted attacks on crypto-specific domains — which had been migrated from Google Domains to Squarespace — were reported. As a result, SEAL, a crypto-focused security team, put together an incident-response team to figure out what was going on, how the attack could be mitigated, and how to get any relevant information to Squarespace itself. At this point, dYdX realized that the earlier incident was likely part of a broader attack against crypto domains, and assisted the investigators. At this time, dYdX also continued to monitor the dydx.exchange domain for any suspicious activity.&lt;br /&gt;
&lt;br /&gt;
On July 14, SEAL published a postmortem on the issue based on their findings, but without much direct information from Squarespace. This postmortem suggested that there were one-or-more technical vulnerabilities in Squarespace that allowed for these attacks to happen.&lt;br /&gt;
&lt;br /&gt;
On July 18, Squarespace posted a longer postmortem which confirmed an exploited security issue with OAuth logins on their site. It included information that the issue was fixed on July 12.&lt;br /&gt;
&lt;br /&gt;
While dYdX decided to change domain registrars, dYdX believed that Squarespace had successfully mitigated the attack and fixed the vulnerability.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - dYdX Exchange DNS Hijacking Attack&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|July 23rd, 2024 9:59:00 AM MDT&lt;br /&gt;
|Twitter Announcement Post&lt;br /&gt;
|The dYdX team posts on Twitter to announce that they are now aware of the hack on the dYdX domain.&lt;br /&gt;
|-&lt;br /&gt;
|July 23rd, 2024 11:48:00 AM MDT&lt;br /&gt;
|Twitter Mention Of Hack&lt;br /&gt;
|A mention on Twitter of the hacked website.&lt;br /&gt;
|-&lt;br /&gt;
|July 23rd, 2024 1:36:00 PM MDT&lt;br /&gt;
|Post About Phishing Attack&lt;br /&gt;
|A post is made which highlights the attack that took place and the phishing transaction which was requested from users.&lt;br /&gt;
|-&lt;br /&gt;
|July 23rd, 2024 1:43:00 PM MDT&lt;br /&gt;
|Website Noted Restored&lt;br /&gt;
|A tweet notes that the website has now been restored and should be safe to use, though users are warned about the potential that their device may have cached the compromised DNS settings.&lt;br /&gt;
|-&lt;br /&gt;
|July 24th, 2024 10:00:00 PM MDT&lt;br /&gt;
|PostMortem Release&lt;br /&gt;
|The dYdX Exchange releases a postmortem on the DNS Hijack attack.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited?&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
&amp;quot;Two users were affected, resulting in a loss of approximately $31,000.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;During the roughly 2 hours that the http://dydx.exchange domain was hijacked, 2 users lost funds totaling about $31k. dYdX Trading is in contact with those users and will ensure that they are made whole.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
The total amount lost has been estimated at $31,000 USD.&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;quot;On July 23, the dydx.exchange domain was discovered to have been compromised. The attacker changed the DNS Nameservers from Cloudflare to DDoS-Guard. The attacker also successfully removed the DNSSEC settings on the domain. The attacker hosted a malicious site which requested that any connected wallets transfer ETH and other ERC20 tokens to the attacker’s Ethereum address.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;On July 23, it was discovered that the dydx.exchange domain was compromised. The attacker changed the DNS Nameservers from Cloudflare to DDoS-Guard. The attacker also successfully removed the DNSSEC settings on the domain. dYdX immediately contacted Squarespace customer support. Squarespace was able to return possession of the domain as well as fix the DNS Nameserver resolution within a couple of hours. The recovery process was delayed for over 30 minutes due to maintenance from one of Squarespace’s third-party vendors which prevented changing the DNS Nameservers back to Cloudflare.&lt;br /&gt;
&lt;br /&gt;
The attacker hosted a malicious site which requested that any connected wallets transfer ETH and other ERC20 tokens to the attacker’s Ethereum address. During this time, dYdX also worked with SEAL and other partners to ensure that popular crypto wallets like Metamask and Phantom would block the site for the duration of the attack. To our knowledge at the time of publishing, 2 users were affected with approximately $31,000 in lost funds due to this attack. dYdX trading is in contact with both affected users and is assisting in securing their wallets and is committed to recovering funds.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;slowmisthackedarchive-15180&amp;quot;&amp;gt;[https://web.archive.org/web/20240826170509/https://hacked.slowmist.io/?c=&amp;amp;page=2 SlowMist Hacked - SlowMist Zone] (Accessed Aug 30, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;dydx-15181&amp;quot;&amp;gt;[https://dydx.exchange/blog/dns-nameserver-hijacking-postmortem DNS Nameserver Hijacking Postmortem] (Accessed Aug 30, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;dydx-15182&amp;quot;&amp;gt;[https://dydx.exchange/ dYdX - Trade Perpetuals on the most powerful trading platform] (Accessed Aug 30, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;llamaonthebrinktwitter-15183&amp;quot;&amp;gt;[https://twitter.com/llamaonthebrink/status/1815797368068956461 @llamaonthebrink Twitter] (Accessed Aug 30, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;open4profittwitter-15184&amp;quot;&amp;gt;[https://twitter.com/open4profit/status/1815806190317683145 @open4profit Twitter] (Accessed Aug 30, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;lawrencechiu14twitter-15185&amp;quot;&amp;gt;[https://twitter.com/LawrenceChiu14/status/1815833455915143587 @LawrenceChiu14 Twitter] (Accessed Aug 30, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;dydxtwitter-15186&amp;quot;&amp;gt;[https://twitter.com/dYdX/status/1815778660453941450 @dYdX Twitter] (Accessed Aug 30, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;dydxtwitter-15187&amp;quot;&amp;gt;[https://twitter.com/dYdX/status/1815780835473129702 @dYdX Twitter] (Accessed Aug 30, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;wazzupcryptotwitter-15188&amp;quot;&amp;gt;[https://twitter.com/Wazzup_Crypto/status/1816060698134302908 @Wazzup_Crypto Twitter] (Accessed Aug 30, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;derektmckinneytwitter-15189&amp;quot;&amp;gt;[https://twitter.com/DerekTMcKinney/status/1816067961339232513 @DerekTMcKinney Twitter] (Accessed Aug 30, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;techflowposttwitter-15190&amp;quot;&amp;gt;[https://twitter.com/TechFlowPost/status/1815930835490726227 @TechFlowPost Twitter] (Accessed Aug 30, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;dydxtwitter-15191&amp;quot;&amp;gt;[https://twitter.com/dYdX/status/1816547431791886756 @dYdX Twitter] (Accessed Aug 30, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;dydxtwitter-15192&amp;quot;&amp;gt;[https://twitter.com/dYdX/status/1816547433691992357 @dYdX Twitter] (Accessed Aug 30, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;dydxtwitter-15193&amp;quot;&amp;gt;[https://twitter.com/dYdX/status/1815835205334073537 @dYdX Twitter] (Accessed Aug 30, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;dydxtwitter-15194&amp;quot;&amp;gt;[https://twitter.com/dYdX/status/1815838667258073289 @dYdX Twitter] (Accessed Aug 30, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;dydxtwitter-15195&amp;quot;&amp;gt;[https://twitter.com/dYdX/status/1815791754756423773 @dYdX Twitter] (Accessed Aug 30, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;goplussecwarextwitter-15196&amp;quot;&amp;gt;[https://twitter.com/GoPlusSecWareX/status/1816046847737356405 @GoPlusSecWareX Twitter] (Accessed Aug 30, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;echoewebtwitter-15197&amp;quot;&amp;gt;[https://twitter.com/Echoeweb/status/1816167063897210882 @Echoeweb Twitter] (Accessed Aug 30, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;parrotcoinstwitter-15198&amp;quot;&amp;gt;[https://twitter.com/parrot_coins/status/1816208045480792452 @parrot_coins Twitter] (Accessed Aug 30, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;veritasweb3twitter-15199&amp;quot;&amp;gt;[https://twitter.com/veritas_web3/status/1815838427402657933 @veritas_web3 Twitter] (Accessed Aug 30, 2024)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>