Milky Crypto News
  • Home
  • Live Coin Market
  • Live Exchange Market
  • Crypto News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Blockchain
  • Regulation
  • Trading
  • Scams
No Result
View All Result
  • Home
  • Live Coin Market
  • Live Exchange Market
  • Crypto News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Blockchain
  • Regulation
  • Trading
  • Scams
No Result
View All Result
Milky Crypto News
No Result
View All Result

Cream Finance Releases Detailed Postmortem Of DNS Attack 

March 18, 2021
in Crypto News
Reading Time: 3min read
A A
0
Cream Finance Releases Detailed Postmortem Of DNS Attack 
1
SHARES
4
VIEWS
ShareShareShareShareShare

DeFi platforms, Cream Finance and PancakeSwap were targeted in a DNS (Domain Name Service) attack on March 15. CREAM Finance announced the DNS attack via Twitter. 

“Our DNS has been compromised by a third party; some users are seeing requests for seed phrase on http://app.cream.finance. DO NOT enter your seed phrase. We will never ask you to submit any private key or seed phrases.“

Cream also pointed out Binance Smart Chain DEX platform PancakeSwap was suffering from the same issue. PancakeSwap had released a warning first and tweeted a confirmation soon after, saying,

“This is now confirmed. DO NOT go to the Pancakeswap site until we confirm it is all clear. NEVER EVER input your seed phrase or private keys on a website. We are working on recovery now. Sorry for the trouble.“

Both platforms added that recovery was currently in progress.

Cream Finance Quick To Recover From Crisis

As soon as the website went down users reported it to Cream, who acted immediately. The team realised that the GoDaddy DNS CNAME record was not pointing to their hosting IP (consistent with their website outage) and updated the DNS A record to the correct IP. The team noticed a phishing page as soon they began root cause analysis. 

Users reported a DNS cache pollution, and the team migrated the DNS to Cloudfare. Further analysis showed that their GoDaddy login credentials were compromised. As they worked on regaining access, CoinGecko, CoinMarketCap, and imToken were alerted to update their website link post and share warning messages to the community.

Cream set up a war room on telegram to ensure the safety of their user’s funds while the team was working on DNS recovery. Soon after their Twitter announcement, they set up two alternative websites, and ~6 hours after the attack, the team reclaimed the ownership of their domain with the help of GoDaddy. 

An hour later, the team announced their domain ownership on Twitter, 

“We have regained control of DNS and everything is back to normal on (link1) and (link2). These sites are now safe to use. Thank you for your patience as we are continue[sic] to monitor this situation.”

Cream Investigates The Attack Thoroughly

The team at Cream Finance released a detailed set of their process and investigation on their medium blog. As per their post, the team uses Google SSO to access their GoDaddy account, and the activity log showed that it was not compromised. 

The first unusual behavior was noticed in GoDaddy’s activity log when a password reset request was sent to the attacker’s email address. However, there was no record of any email address change. The team reproduced the scenario with their GoDaddy account, signing with their Google account. 

A change in email address should produce a record, but the team did not experience it. They could only access a part of the activity log on GoDaddy. They tried to access all but it threw up an “unexpected error.” They confirmed the IP of their attacker to be the same as the one on the activity logs of PancakeSwap, who uses GoDaddy too. 

Cream will update their post on medium as further information becomes available.

User’s Funds Remained Safe Throughout The Attack

Cream’s smart contracts and user’s funds remained safe as the DNS hijacking only affected their website. They have deployed a decentralized frontend in IPFS, ensuring that users get to access services deployed by the platform. The team stated they have complete control of their ENS record, preventing such attacks in the future. 

Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice. 

Credit: Source link

ShareTweetSharePinShare
Previous Post

Famous TikTok user ‘Doggface’ is selling his NFT for $500,000—but there’s a catch

Next Post

Little-Known Crypto Project Packs Groundbreaking NFT Features, Says Analyst and Trader Josh Rager

Related Posts

$1.3B Worth Of Ransomware Payments In 2020-21: Report
Crypto News

ESET Research Issues Crypto Theft Warning, Seed Phrases At Risk

March 30, 2022
Robinhood Launches Crypto Wallet In Beta
Crypto News

Robinhood’s Crypto COO Leaves, Founds New Crypto Startup

March 30, 2022
Axie Infinity’s Ronin Network Exploited, $625m In USDC and ETH Stolen
Crypto News

Axie Infinity’s Ronin Network Exploited, $625m In USDC and ETH Stolen

March 29, 2022
Hedera Hashgraph Opens $155m DeFi Fund
Crypto News

Hedera Hashgraph Opens $155m DeFi Fund

March 29, 2022
Load More
Next Post
Little-Known Crypto Project Packs Groundbreaking NFT Features, Says Analyst and Trader Josh Rager

Little-Known Crypto Project Packs Groundbreaking NFT Features, Says Analyst and Trader Josh Rager

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

$10,000,000,000,000 Asset Management Firm BlackRock Exploring Support for Crypto Assets

$10,000,000,000,000 Asset Management Firm BlackRock Exploring Support for Crypto Assets

March 25, 2022
Binance Invests another $5m in Metaverse Startup Ultiverse

Binance Invests another $5m in Metaverse Startup Ultiverse

March 25, 2022
DOJ Charges Two People in Million-Dollar Scheme to Defraud Investors – Regulation Bitcoin News

DOJ Charges Two People in Million-Dollar Scheme to Defraud Investors – Regulation Bitcoin News

March 26, 2022
Biggest department store in Europe sets its sights on cryptocurrency

Biggest department store in Europe sets its sights on cryptocurrency

March 28, 2022
Cardano Double Wins – Hits NFT Milestone And Launches First Hydra Node

Cardano Double Wins – Hits NFT Milestone And Launches First Hydra Node

March 24, 2022
FinTech Figure Launches Cryptocurrency Mortgage Products

FinTech Figure Launches Cryptocurrency Mortgage Products

March 24, 2022
Milky Crypto News

This is an online news portal that aims to provide the latest crypto news and real-time updates around the world. Feel free to get in touch with us!

What’s New Here!

  • MetaMask Adds Apple Pay Integration, Expands Options for Buying Cryptos
  • ESET Research Issues Crypto Theft Warning, Seed Phrases At Risk
  • Nasdaq-Listed Microstrategy Obtains $205 Million Bitcoin-Backed Loan to Buy More BTC – Finance Bitcoin News
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 - MilkyCrypto.io - All rights reserved!

No Result
View All Result
  • Home
  • Live Coin Market
  • Live Exchange Market
  • Crypto News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Blockchain
  • Regulation
  • Trading
  • Scams