Curve Finance Targeted in DNS Hijacking Attack, Users Warned Off Main Site
Curve suffers a DNS hijack, redirecting users to a fake site; smart contracts remain secure, but trust is shaken.
Curve Finance, a leading decentralized finance protocol, has become the latest high-profile target in a DNS hijacking attack that compromised its primary website. The incident, which unfolded on Monday, redirected visitors from Curve’s official domain, “curve.fi,” to a fraudulent clone engineered to steal funds from unsuspecting users.
The attack exploited the protocol’s Domain Name System (DNS) records—a layer of internet infrastructure not directly related to blockchain but crucial for directing web traffic. By altering these records, attackers seamlessly rerouted users to a fake website mimicking Curve’s interface. Malicious scripts embedded in the fake site prompted users to approve transactions, unknowingly granting token permissions to attacker-controlled wallets.
Curve’s development team was quick to respond. They confirmed that the breach was confined to the DNS layer, with no impact on the protocol’s smart contracts or on-chain infrastructure. Nevertheless, they advised users to avoid the compromised “curve.fi” domain and instead use “curve.finance” as a temporary safe access point.
In a public statement, Curve announced it had launched a full-scale investigation into the breach and was collaborating with its domain registrar and external cybersecurity partners. The team committed to strengthening infrastructure protections to prevent future incidents, noting that some safeguards were already in place before the attack occurred.
This is not the first time Curve has faced front-end vulnerabilities. A similar DNS hijack in 2022 resulted in losses exceeding $570,000. In 2023, the protocol was also affected by a vulnerability in the Vyper programming language that cost DeFi users over $24 million. Just days before this latest breach, Curve’s official X (formerly Twitter) account was temporarily compromised to promote a malicious link.
The recent attack highlights a growing concern within the DeFi space: the vulnerability of user-facing infrastructure. Even with secure smart contracts, projects remain susceptible to exploits targeting domains, hosting services, and web interfaces. These attacks can be especially dangerous, as they often go undetected by end users, who may trust the familiar look of a site and unknowingly interact with malicious clones.
Despite these challenges, Curve remains a major player in the DeFi ecosystem. With more than $2.3 billion in total value locked and deployments across 22 blockchain networks, it is a cornerstone of stablecoin liquidity provision. However, repeated breaches are testing user confidence and raising broader questions about operational security in the decentralized sector.



