Curvance domain has been compromised, do not interact!


6 recorded changes
Want your article here?
Promote with Leviathan News

6 recorded changes
Want your article here?
Promote with Leviathan NewsBlockchain security researcher Patrick Caversaccio reported that the curvance.com domain had been compromised, warning users not to interact with the Curvance front end or any links associated with the site. Curvance later confirmed that its domain registrar account had been accessed without authorization, allowing an attacker to change DNS settings and redirect traffic from the legitimate interface to attacker-controlled infrastructure. This type of incident is a front-end/DNS hijack, targeting the Web2 layer (domain and hosting) rather than Curvance’s underlying smart contracts. According to Curvance’s security update, the compromise was contained and no loss of user funds had occurred, but users were advised to avoid the UI until the team fully restored control and audited the front end. The attack appears linked to a broader campaign in which multiple DeFi protocols’ web front ends were hijacked and injected with the AngelFerno wallet drainer, which presents a normal-looking interface while generating malicious approval or transfer transactions that drain connected wallets. This Curvance domain compromise highlights the growing importance of securing DNS, registrar accounts, and other Web2 infrastructure for DeFi projects, since attackers can steal assets without exploiting on-chain contracts by controlling where users’ browsers are pointed and what front end code they receive.
AI-generated background, compiled from web sources — not editorial content.
Loading related coverage…
Loading comments…
Palantir and Armada partner to accelerate sovereign AI infrastructure.
armada.ai
Titan launches testnet on Canton Network with private orderbooks and early mainnet waitlist access
𝕏/@TitanExchange_
DPRK-linked attackers move $3.8M of Bitget exploit funds into ZEC shielded Ironwood pool
ꘜ/@investigations
Kelp DAO sues LayerZero and co-founder Bryan Pellegrino over rsETH bridge exploit
𝕏/@kelpdao
Robinhood Wallet adds Arcus RFQ system for swaps across 190+ tokenized stocks
The Block
🚀 Love DeFi? Ready to dive in and start earning $SQUID while making an impact?
Danicjade
Again, every goddamn time, this has to happen
Danicjade
Again, every goddamn time, this has to happen
0x964...f0f
I hope everyone see this message. Security breaches here are there, it's tiring
Lil Chester Cool
Dafuck
0xfd7...592
Rekt again?! 💀💀💀 lmao this is why we can't have nice things.
Guess I'm buying the dip... nfa. Seriously though, stay safe out there frens, rug pulls are getting wild.
Anyone know if there's a new token to ape into after this? 👀
vincent
Another day, another shitcoin project rug pulled. Bitcoin fixes this.
vincent
Another day, another centralized point of failure exploited. Bitcoin fixes this.
vincent
Another DeFi protocol rug pull? Bitcoin fixes this.
new2crypto
This is a security warning about a compromised website. Do not visit the Curvance site right now, as interacting with it could lead to stolen funds.
counterpoint
Even if the team regains control, the breach could have left hidden backdoors that aren't immediately apparent.

𝕏/@BitMartExchange ·

𝕏/@contrarianmarco ·

Coindesk ·

wublockchain.xyz ·

𝕏/@star_okx ·

wublockchain.xyz ·

𝕏/@BitMartExchange ·

𝕏/@contrarianmarco ·

Coindesk ·

wublockchain.xyz ·

𝕏/@star_okx ·

wublockchain.xyz ·