📈 Get daily crypto insights that make you smarter about your money

How the Squarespace Migration Created a Perfect Storm for Crypto DNS Hijacking

The cryptocurrency ecosystem faced a significant security crisis on July 11, 2024, as multiple high-profile DeFi protocols fell victim to a coordinated DNS hijacking campaign. Celer Network, Compound Finance, Pendle Finance, and Unstoppable Domains all reported losing control of their official websites, with attackers redirecting traffic to wallet-draining phishing kits. With Bitcoin trading at $57,344 and Ethereum at $3,100, the stakes for users navigating these compromised platforms could not have been higher.

The Exploit Mechanics

The attack vector exploited a critical weakness in the domain migration from Google Domains to Squarespace, which was completed in June 2024. When Squarespace acquired Google Domains and migrated customer accounts, multi-factor authentication was disabled as a technical measure to prevent administrators from being locked out during the transition. This created a window of vulnerability that sophisticated threat actors quickly identified and exploited.

According to a security advisory published by researchers from Paradigm and Metamask, the attackers leveraged previously stolen or leaked credentials to access domain admin panels. Without MFA as a barrier, the login process required only a username and password — credentials that had been circulating in data breaches for months or even years. Once inside, the attackers modified DNS records to point legitimate domain names to their own malicious servers.

The phishing kits deployed on these hijacked domains were remarkably sophisticated. They mimicked the legitimate interfaces of Celer Network, Compound Finance, and Pendle Finance with near-perfect accuracy, making it virtually impossible for an average user to distinguish the fake site from the real one. The primary goal was to trick users into connecting their wallets, at which point the malicious smart contracts would drain funds through automated transaction signing.

Affected Systems

The scope of the attack was particularly alarming because of the caliber of the targeted platforms. Celer Network, a major cross-chain bridge protocol, issued the first public warning on July 11, alerting the community that its domain had been compromised. Compound Finance, one of the oldest and most trusted DeFi lending protocols, confirmed shortly after that its domain had also been hijacked.

Pendle Finance, a yield-trading protocol that had seen significant growth in 2024, and Unstoppable Domains, a blockchain naming service, rounded out the confirmed victims. All four platforms had one thing in common: their domains had been migrated from Google Domains to Squarespace during the June transition period.

Beyond the immediate website compromises, researchers warned that the attackers could have also hijacked MX records for email servers associated with these domains. This would have given them the ability to intercept password reset emails, two-factor authentication codes, and other sensitive communications — potentially enabling deeper penetration into organizational infrastructure.

The Mitigation Strategy

The response to the crisis was swift and community-driven. Cryptocurrency experts immediately compiled lists of domains hosted on Squarespace and published them on GitHub, warning users to avoid accessing these sites until administrators confirmed they had secured their domains and re-enabled MFA. The security research team from Paradigm and Metamask published a detailed PDF advisory outlining the attack methodology and recommended countermeasures.

Domain administrators were advised to immediately review their Squarespace accounts, change all passwords, remove any unauthorized users with access to DNS records, revert any recent DNS changes, and re-enable multi-factor authentication. The incident also prompted broader discussions about the dangers of centralized domain registration for decentralized projects.

Lessons Learned

This incident laid bare a fundamental tension in the cryptocurrency space: while the protocols themselves may be decentralized and secure, the infrastructure used to access them — domain names, DNS servers, hosting providers — remains stubbornly centralized and vulnerable. The Squarespace migration created a systemic risk that affected multiple unrelated projects simultaneously, demonstrating how a single point of failure in the traditional internet infrastructure can cascade across the entire DeFi ecosystem.

The attack also highlighted the importance of defense-in-depth strategies. Projects that had implemented additional security measures beyond standard DNS configuration — such as content security policies, subresource integrity checks, and browser-extension-based verification — were better positioned to protect their users even when their domains were compromised.

User Action Required

For users who interacted with Celer Network, Compound Finance, Pendle Finance, or Unstoppable Domains around July 11, 2024, immediate action is recommended. Review wallet transaction histories for any unauthorized approvals, particularly unlimited token allowances to unknown contracts. Revoke any suspicious approvals using tools like Revoke.cash or Etherscan token approval checkers. If you entered a seed phrase or private key on any of these sites during the attack window, immediately transfer all assets to a new wallet. Moving forward, always verify website authenticity through multiple channels before connecting a wallet or signing transactions.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research and consult with security professionals before making decisions about your digital assets.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “How the Squarespace Migration Created a Perfect Storm for Crypto DNS Hijacking”

  1. Compound is one of the oldest DeFi protocols and they got caught slipping on DNS. if they cant manage registrar security what hope do newer protocols have

  2. dns_graveyard_

    Squarespace disabling MFA during migration to prevent lockouts is the single dumbest security decision of 2024. they basically rolled out the red carpet for credential stuffing on domains holding billions in TVL

  3. registry_lock_

    squarespace disabling MFA during migration is the kind of call no security engineer would ever greenlight. some PM made that call and nobody pushed back

  4. registry_lock Compound Celer and Pendle all could have enabled registry lock for free and none did it. weeks of warning between the google domains announcement and the hijacks

    1. registry_lock_ exactly. registry lock costs nothing and would have stopped every single hijack. the due diligence was zero until wallets started draining

      1. registry_lock_

        dns_widow_ registry lock is free and takes 5 minutes to enable. the fact that Compound and Celer didnt have it on is negligent. protocols will blame Squarespace but the tooling existed

  5. Compound and Pendle losing their domains because a domain registrar disabled MFA is absurd. registry lock costs 0 dollars and would have prevented every single one of these hijacks

  6. squarespace acquired millions of domains from google and nobody in the crypto space audited their registrar security until wallets were already draining. due diligence is always retrospective

  7. the real lesson is checking your own DNS registrar settings before a migration happens. Celer and Compound had weeks to move registrars after the Google Domains announcement. nobody did

    1. compound celer and pendle had weeks to enable registry lock after the google domains announcement. costs basically nothing. the real lesson is protocols treating DNS as someone elses problem

  8. paradigm and metamask researchers dropping the advisory before Squarespace even acknowledged the issue. tells you everything about who actually protects users in this space

    1. wallet drainer phishing kits were live within hours of the DNS takeover. these werent opportunists, they were pre-positioned

      1. pre-positioned and waiting for the migration window. this wasnt some script kiddie operation, the timing was surgical

  9. BTC at 57K and ETH at 3100. imagine checking compound finance and getting wallet drained because your DNS provider forgot to enable MFA. layers of failure

  10. the fact that this was preventable is what gets me. disabling MFA as a technical measure during migration is negligent

    1. disabling MFA during migration is like removing the locks from your house because the new tenant might lose their keys. absurd logic

      1. Lena K. disabling MFA during migration is standard IT practice to avoid lockouts. the real failure was squarespace not forcing a reset within 48 hours of transfer completion

      2. dns_graveyard_

        Lena K. removing MFA during migration is the kind of decision no security engineer would ever approve. some PM overrode it

    2. squarespace response was basically we are aware and investigating while wallets were being drained in real time. peak corporate crisis management

      1. squarespace had one job after acquiring google domains and they fumbled the security handoff. corporate crisis management indeed

  11. the cascading failures here are wild. ISP credentials leak -> MFA disabled during migration -> DNS changed -> phishing kit live. each layer assumed the other was secure

    1. dns_grimoire_

      dns_oracle each layer assumed the other was secure is the perfect summary. defense in depth only works if every layer actually has defenses

  12. Compound, Celer, Pendle all compromised in the same window. Squarespace had weeks to fix MFA and did nothing until wallets were drained

  13. squarespace disabled MFA during migration as a security measure. thats not a security measure thats a liability waiver. every defi protocol should have moved registrars the day that announcement dropped

  14. Celer Compound Pendle all getting hit the same day means attackers were watching the Squarespace migration timeline like hawks. coordinated hit not opportunistic

  15. dns_drift_kep registry lock is free or like 50 bucks a year. no excuse for a protocol holding billions in TVL to skip it

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$86,323.00+0.6%ETH$2,744.25+0.4%SOL$117.29-0.3%BNB$788.37-1.7%XRP$1.57+5.7%ADA$0.2526+3.9%DOGE$0.1001+4.7%DOT$1.17-0.6%AVAX$11.16-0.2%LINK$13.04+0.6%UNI$9.28+5.4%ATOM$1.75-2.0%LTC$61.43-1.2%ARB$0.2152-6.8%NEAR$4.43+9.9%FIL$1.01+4.7%SUI$1.01-0.2%BTC$86,323.00+0.6%ETH$2,744.25+0.4%SOL$117.29-0.3%BNB$788.37-1.7%XRP$1.57+5.7%ADA$0.2526+3.9%DOGE$0.1001+4.7%DOT$1.17-0.6%AVAX$11.16-0.2%LINK$13.04+0.6%UNI$9.28+5.4%ATOM$1.75-2.0%LTC$61.43-1.2%ARB$0.2152-6.8%NEAR$4.43+9.9%FIL$1.01+4.7%SUI$1.01-0.2%
Scroll to Top