AInvest Newsletter
Daily stocks & crypto headlines, free to your inbox


Aerodrome Finance, the leading decentralized exchange (DEX) on
Layer 2 network Base, and Velodrome, its counterpart on , early Saturday, prompting urgent warnings for users to avoid their primary domains and use decentralized mirrors. The incident, , allowed attackers to reroute traffic to phishing sites designed to trick users into signing malicious transactions. Both platforms emphasized that their underlying smart contracts remain secure, but users are advised to revoke recent token approvals and avoid unverified domains .The attack mirrors a similar incident in late 2023, when Aerodrome and Velodrome's front-ends were compromised,
. This latest breach occurred just days after Aerodrome under the unified "Aero" ecosystem, aiming to consolidate liquidity across Base and Optimism. Despite the disruption, the AERO token's price , trading at approximately $0.67, a 2% increase over the prior 24 hours.
The DNS hijacking exploited vulnerabilities in centralized domain providers, redirecting users to malicious sites that mimicked the DEXs' interfaces.
, including seemingly innocuous signature requests followed by aggressive approval demands for NFTs, ETH, and stablecoins. Aerodrome's team after identifying unusual domain activity and swiftly shut down access to compromised domains like aerodrome.finance and aerodrome.box, such as aero.drome.eth.limo. Velodrome similarly advised users to avoid its centralized domains and leverage decentralized alternatives .The attack highlights ongoing risks in decentralized finance (DeFi), where front-end vulnerabilities - unlike on-chain smart contract breaches - can be exploited without directly compromising protocol infrastructure.
that liquidity pools and protocol treasuries remain intact. However, the incident underscores the need for robust domain security measures, particularly for projects relying on centralized DNS services.Aerodrome's team is investigating the breach alongside its domain provider, My.box, and
to resolve the issue. The DEX also for users to revoke recent token approvals, mitigating potential risks from lingering malicious permissions.The coordinated nature of the attack raises concerns about broader vulnerabilities in domain management systems, with multiple DeFi platforms potentially exposed to similar threats. As the industry continues to prioritize decentralization, the reliance on centralized DNS services remains a critical point of contention.
Quickly understand the history and background of various well-known coins

Dec.02 2025

Dec.02 2025

Dec.02 2025

Dec.02 2025

Dec.02 2025
Daily stocks & crypto headlines, free to your inbox
Comments
No comments yet