Voted Coins
follow us on twitter . like us on facebook . follow us on instagram . subscribe to our youtube channel . announcements on telegram channel . ask urgent question ONLY . Subscribe to our reddit . Altcoins Talks Shop Shop


This is an Ad. Advertised sites are not endorsement by our Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise Here

Author Topic: More than 220 DeFi Protocols Still ‘at Risk’ From Squarespace DNS Hijack  (Read 1113 times)

Offline Yamane_Keto

  • Hero Member
  • *
  • *
  • Activity: 728
  • points:
    35364
  • Karma: 57
  • Trade Count: (0)
  • Referrals: 2
  • Last Active: March 18, 2025, 02:21:20 AM
    • View Profile

  • Total Badges: 13
    Badges: (View All)
    One year Anniversary 500 Posts Search
Inferno Drainer's wallet kit allows cybercriminals to steal funds from unsuspecting users. It operates by prompting users to sign malicious transactions that give the attacker control over their digital assets.

Once the transaction is signed, the drainer kit swiftly transfers the funds from the victim's wallet to the attacker's address. The kit is often deployed through phishing websites or compromised domains.

The Inferno Drainer group has been active for some time, targeting various DeFi protocols and exploiting different vulnerabilities. Their use of shared infrastructure makes it easier for security firms to track and identify related attacks, something Ben-Natan was quick to point out.


Such attacks can be made more difficult by making any DNS updates require a signature from the user's wallet. Thus, hackers will need to hack each device separately, but you should be more careful when linking your wallet to bridges or decentralized finance (DeFi) protocols.

Altcoins Talks - Cryptocurrency Forum


This is an Ad. Advertised sites are not endorsement by our Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise Here


Offline joniboini

  • Legendary
  • *
  • *
  • Activity: 2000
  • points:
    214423
  • Karma: 128
  • Coinomize.biz
  • Trade Count: (0)
  • Referrals: 0
  • Last Active: Today at 05:52:10 AM
    • View Profile

  • Total Badges: 14
    Badges: (View All)
    One year Anniversary Karma Good Poll Voter
I wonder if a simple extension showing the domain IP address can also help mitigate an attack like this. Wouldn't this attack be possible because the DNS redirects the request to phishing websites, so if we compare the IP we should notice they are different? Making our wallets save DNS request history can also bring another problem of privacy IMO.

Altcoins Talks - Cryptocurrency Forum


This is an Ad. Advertised sites are not endorsement by our Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise Here


Offline Yamane_Keto

  • Hero Member
  • *
  • *
  • Activity: 728
  • points:
    35364
  • Karma: 57
  • Trade Count: (0)
  • Referrals: 2
  • Last Active: March 18, 2025, 02:21:20 AM
    • View Profile

  • Total Badges: 13
    Badges: (View All)
    One year Anniversary 500 Posts Search
I wonder if a simple extension showing the domain IP address can also help mitigate an attack like this. Wouldn't this attack be possible because the DNS redirects the request to phishing websites, so if we compare the IP we should notice they are different? Making our wallets save DNS request history can also bring another problem of privacy IMO.
If humans remembered or focused on IP addresses, we would not need DNS, which is the Domain Name System, which assigns an appropriate domain name to each specific IP address.
The ideal way is to modify the host file on your computer and allow visits to specific IP addresses and block any IP address that is not in the file. browsing experience will be bad but safe.

Offline Stompix

  • Legendary
  • *
  • *
  • Activity: 3045
  • points:
    252098
  • Karma: 270
  • Bitcoin Mixer| Since 2019
  • Trade Count: (0)
  • Referrals: 0
  • Last Active: Today at 01:17:12 AM
    • View Profile

  • Total Badges: 17
    Badges: (View All)
    One year Anniversary 2500 Posts Karma Bad
If humans remembered or focused on IP addresses, we would not need DNS, which is the Domain Name System, which assigns an appropriate domain name to each specific IP address.

Hihi we will just note down every IP and check it like we do crypto addresses.
After a week we will be all talking 87.17.181.11.34.171.18 

The ideal way is to modify the host file on your computer and allow visits to specific IP addresses and block any IP address that is not in the file. browsing experience will be bad but safe.

It would be crazy, google itself has about 20 main domains with a ton of IPs, if you plan on still using social media and all 3rd party links on it you will probably waste half a day each month whitelisting IPs, and still even that won't save you if the website itself is compromised and the malware is feed directly.

Unfortunately, the more you secure something the tired you get from actually using that stuff.


 

ETH & ERC20 Tokens Donations: 0x2143F7146F0AadC0F9d85ea98F23273Da0e002Ab
BNB & BEP20 Tokens Donations: 0xcbDAB774B5659cB905d4db5487F9e2057b96147F
BTC Donations: bc1qjf99wr3dz9jn9fr43q28x0r50zeyxewcq8swng
BTC Tips for Moderators: 1Pz1S3d4Aiq7QE4m3MmuoUPEvKaAYbZRoG
Powered by SMFPacks Social Login Mod