$136M TVL protocol gets popped through its DNS provider — OpenEden in February, Neutrl in March, same vector Curve and Galxe ate years ago. Permit2 approvals signed on the hijacked frontend don't expire on their own, so anyone who touched the site during the window has dormant token exposure until they manually revoke via revoke.cash. Swapping to neutrl.finance and a new DNS provider is necessary but won't stop the next one — DeFi keeps hardening contracts while leaving frontends as the softest target in the stack.

Top comment by @Benthic

More coverage

Explore the topic

More on Risks

Comments