1. Home
  2. Balancer

Balancer

Balancer blames ‘social engineering attack’ on DNS provider for website hijack

Blockchain security firms SlowMist and CertiK also believe the crypto wallet drainer Angel Drainer was involved in the estimated $238,000 exploit.

The team behind Balancer, an Ethereum-based automated market maker, believes a social engineering attack on its DNS service provider was what led to its website’s frontend being compromised on Sept. 19, leading to an estimated $238,000 in crypto stolen.

“After investigation, it is clear that this was a social engineering attack on EuroDNS, the domain registrar used for .fi TLDs,” the firm explained in a Sept. 20 X post.

Approximately 8 hours after the first warning of the attack, Balancer said its decentralized autonomous organization (DAO) was actively addressing the DNS attack and was working to recover the Balancer UI.

At 5:45 pm UTC on Sept. 20, Balancer said it was successful in securing the domain and bringing it back under the control of Balancer DAO. It also confirmed its subdomains “app.balancer.fi” and other “balancer.fi” are safe to use again.

However, it suggested any other projects using the same top-level domain should consider moving to a more secure registrar. 

EuroDNS is a Luxembourg-based domain name registrar and DNS service provider. Cointelegraph has reached out to EuroDNS for comment.

Angel Drainer involved

Blockchain security firms SlowMist and CertiK reported that the attacker employed Angel Drainer phishing contracts.

SlowMist said the exploiters attacked the Balancer’s website via Border Gateway Protocol hijacking — a process where hackers take control of IP addresses by corrupting internet routing tables.

The hackers then induced users to “approve” and transfer funds via the “transferFrom” function to the Balancer exploiter, it explained.

Related: Breaking: ‘All funds are at risk' — Steadefi exploited in ongoing attack

The hacker, whom SlowMist believes may be related to Russia, has already bridged some of the stolen Ether (ETH) to Bitcoin (BTC) addresses via THORChain before eventually being bridging the ETH back to Ethereum, blockchain security firm SlowMist explained on Sept. 20.

SlowMist stated in an earlier post that the hacker transferred about 15 wrapped-Ether (wETH.e) on the Avalanche blockchain.

Meanwhile, despite Balancer confirming its subdomains, balancer.fi to now be safe, visits to the website still shows “Deceptive site ahead” warning when attempting to access the Balancer’s website.

Balancer’s website as of Sept. 20 at 10:22 pm UTC. Source: Balancer.

Cointelegraph reached out to Balancer to confirm the amount of funds lost but did not receive an immediate response.

Magazine: $3.4B of Bitcoin in a popcorn tin: The Silk Road hacker’s story

Stripe bringing back crypto payments, this time with a stablecoin

DeFi protocol Balancer frontend is under attack, urges users to stay away

The platform notified its community on Sept. 19 at 11:49 pm UTC, urging users to not interact with Balancer's protocol until further notice.

Balancer, an Ethereum-based decentralized finance protocol has confirmed its user interface is currently "under an attack."

The platform notified its community on Sept. 19 at 11:49 pm UTC, urging users to not interact with Balancer's protocol until further notice.

Balancer said the details of the attack are under investigation. The firm hasn't confirmed whether user funds are safe at this point in time.

However, one blockchain analyst, ZachXBT claims $238,000 was stolen within the first 30 minutes of Balancer breaking the news.

This is the second theft from Balancer in a month, after it warned of a critical vulnerability on Aug. 22, which resulted in a $2 million exploit several days later.

This is a developing story, and further information will be added as it becomes available.

Stripe bringing back crypto payments, this time with a stablecoin

Over $200,000,000 Withdrawn From Balancer (BAL) Pools After Project Announces ‘Critical Vulnerability’

Over 0,000,000 Withdrawn From Balancer (BAL) Pools After Project Announces ‘Critical Vulnerability’

The total value locked (TVL) on Balancer (BAL) dropped by more than $200 million over a period of 24 hours after the decentralized finance (DeFi) protocol advised users to withdraw liquidity as a precautionary measure. In a post on social media platform X, the Balancer team says it discovered a critical vulnerability in a number […]

The post Over $200,000,000 Withdrawn From Balancer (BAL) Pools After Project Announces ‘Critical Vulnerability’ appeared first on The Daily Hodl.

Stripe bringing back crypto payments, this time with a stablecoin

Decentralized Exchange Pancakeswap to Launch Version 3 Iteration in April

Decentralized Exchange Pancakeswap to Launch Version 3 Iteration in AprilOn March 4, the decentralized exchange Pancakeswap announced that the team plans to launch its version three (v3) iteration of the platform during the first week of April 2023. Pancakeswap v3 will provide new features and improve liquidity alongside enhancements in interface accessibility and the decentralized exchange (dex) platform’s yield farming experience. Pancakeswap Announces Version […]

Stripe bringing back crypto payments, this time with a stablecoin

Total Value Locked in Defi Surpasses $50 Billion Mark for First Time Since FTX Collapse

Total Value Locked in Defi Surpasses  Billion Mark for First Time Since FTX CollapseCrypto prices have surged in value over the past few days, and the total value locked (TVL) in decentralized finance (defi) has surpassed the $50 billion mark for the first time since the collapse of FTX. As of Feb. 16, 2023, the TVL in defi is $51.1 billion, with the liquid staking protocol Lido accounting […]

Stripe bringing back crypto payments, this time with a stablecoin

Decentralized Exchange Trading Volumes Remain Lackluster in the New Year, Uniswap Leads the Way with Daily Swaps

Decentralized Exchange Trading Volumes Remain Lackluster in the New Year, Uniswap Leads the Way with Daily SwapsAccording to statistics, decentralized exchange (dex) monthly trading volumes have dropped significantly since Jan. 2022. After a brief spike in volume in Nov. 2022, dex trade volumes have been lackluster for the past 44 days. As of Jan. 14, 2023, Uniswap version three (V3) has the highest trade volume during the past 24 hours at […]

Stripe bringing back crypto payments, this time with a stablecoin

TrueUSD and Balancer Offer Liquidity Providers TUSD and BAL Rewards From Stablecoin Pool Incentive Program

TrueUSD and Balancer Offer Liquidity Providers TUSD and BAL Rewards From Stablecoin Pool Incentive ProgramPRESS RELEASE. Singapore, Singapore / April 4th / – TrueUSD (TUSD) and Balancer (BAL) Automated Market Maker (AMM) partnered up with Polygon to offer liquidity providers with TUSD and BAL rewards from a stablecoin pool incentive program last November. The program incentivizes liquidity providers to add TUSD-DAI-USDC-USDT liquidity to the Polygon ecosystem. In return for […]

Stripe bringing back crypto payments, this time with a stablecoin

Value Locked in Defi Sheds $55 Billion in 2 Months, Ethereum’s Defi Dominance Loses 14%

Value Locked in Defi Sheds  Billion in 2 Months, Ethereum’s Defi Dominance Loses 14%The crypto-economy has been sliding in value during the last 48 hours as the current market valuation for all 13,000+ crypto assets is $1.83 trillion. Furthermore, the total value locked (TVL) in decentralized finance (defi) protocols has slipped below the $200 billion mark to $196.02 billion on Sunday morning (EST). Meanwhile, Ethereum’s dominance is 55.54% […]

Stripe bringing back crypto payments, this time with a stablecoin