OceanAltOceanAlt

Security incident · 2022-06-24

Convex Finance

According to the public DefiLlama incident dataset, Convex Finance (Ethereum) suffered a security incident on 2022-06-24, with about $14K reported lost.

Date2022-06-24
Reported loss$14K
ChainEthereum
Target typeDeFi Protocol
Technique classFrontend & Infrastructure
TechniqueDNS Hijack
Bridge incidentNo
Within 2022#167 by loss that year, 0.0% of all reported losses that year

How this kind of attack works

The website, domain or hosting was hijacked, and users signed transactions that sent funds to the attacker from a page that looked normal.

Would a pre-payment check have helped

Partly applies

When a frontend or domain is hijacked the payee address is freshly generated and on no list, but the hijacked host is often already in public phishing feeds, so endpoint screening catches part of this class.

Other incidents with the same technique

Sources

This page restates public reports and is not OceanAlt's judgment of any party. To report an error, email business@oceanalt.com; we review within 48 hours.

← Back to incidents