GSD-2022-1004953

Source
https://data.gsd.id/GSD-2022-1004953
Import Source
https://github.com/cloudsecurityalliance/gsd-database/blob/main/2022/1004xxx/GSD-2022-1004953.json
JSON Data
https://api.osv.dev/v1/vulns/GSD-2022-1004953
Withdrawn
2023-03-14T07:01:09Z
Published
2022-08-09T23:36:36Z
Modified
2023-03-14T07:01:09Z
Summary
DNS hijack in Smart contract version website serving smartcontract on 2022-08-09
Details

The curve.finance web site was DNS hijacked on 2022-08-09 and a new smart contract that drains victims wallets if accepted is being served. Previously the DNS was registered through GoDaddy. The attack was partially mitigated through a white hat hacker that executed a SYN flooding attack against the new IP addresses serving the malicious smart contract, limiting the ability for victims to connect and be attacked.

References

Affected packages