📈 Get daily crypto insights that make you smarter about your money

How to Protect Your Crypto From Domain Hijacking: Lessons From the Layerswap $100K Attack

On March 20, 2024, cryptocurrency bridge service Layerswap suffered a devastating domain hijacking attack that redirected users to a malicious phishing site, draining approximately $100,000 from around 50 wallets. The attackers compromised Layerswap’s GoDaddy account, seized control of the layerswap.io domain, and even attempted to take over the company’s Twitter account to prevent them from warning users. If you think your crypto is safe just because you use a hardware wallet, this incident shows that the attack surface extends far beyond the blockchain itself.

The Basics

Domain hijacking occurs when an attacker gains control of a website’s domain registration — the digital address that tells your browser where to find a website. In the crypto world, this is particularly dangerous because users routinely connect their wallets to websites for trading, staking, and bridging. When a legitimate domain is redirected to a malicious site, users may unknowingly connect their wallets to a fake interface that drains their funds.

In the Layerswap incident, the attacker gained access to the company’s GoDaddy account at approximately 19:40 UTC on March 20, 2024. The domain was redirected to a phishing site that looked identical to the real Layerswap interface. Users who visited the site and connected their wallets had their funds siphoned. The attack lasted until 23:07 UTC, when Layerswap finally regained control of the domain — nearly three and a half hours of exposure.

Why It Matters

Domain hijacking attacks are becoming more frequent and more sophisticated in the crypto space. Unlike smart contract exploits that target code vulnerabilities, domain attacks target the internet infrastructure layer — domain registrars, DNS servers, and hosting providers. These attacks can affect even the most security-conscious projects because they exploit weaknesses in third-party services rather than the project’s own code.

With Bitcoin trading near $65,491 and the total crypto market cap above $2.6 trillion, the financial incentives for these attacks have never been greater. A single successful domain hijack can net attackers hundreds of thousands of dollars in minutes. The Layerswap attack happened on the same day as the $1.8 million Dolomite Exchange hack and the $4.6 million Super Sushi Samurai exploit, illustrating the sheer volume of attack vectors targeting crypto users.

Getting Started Guide

Protecting yourself from domain hijacking attacks requires a multi-layered approach. Here are the essential steps every crypto user should follow:

Step 1: Verify URLs manually. Always type the URL of any crypto service directly into your browser rather than clicking links from emails, social media, or messaging apps. Bookmark the correct URLs for services you use regularly.

Step 2: Check for SSL certificates. Look for the padlock icon in your browser’s address bar and verify the domain name matches exactly. However, note that attackers can also obtain SSL certificates for hijacked domains, so this alone is not sufficient protection.

Step 3: Use browser extensions. Security-focused browser extensions like PocketUniverse or Wallet Guard can detect suspicious wallet connection requests and warn you before you interact with a potentially compromised site.

Step 4: Enable transaction simulations. Modern wallets like MetaMask offer transaction simulation features that show you what a transaction will do before you sign it. If a routine bridge or swap operation shows unusual token transfers, abort immediately.

Step 5: Set up hardware wallet limits. Use a hardware wallet for large holdings and set daily transaction limits where possible. This limits the damage even if you do connect to a malicious site.

Common Pitfalls

The most dangerous mistake is trusting a URL just because it looks familiar. Sophisticated attackers create convincing replicas of legitimate sites that can fool even experienced users. Another common pitfall is ignoring security alerts — when projects announce security incidents on social media, users should immediately stop interacting with the service until an all-clear is given. Finally, many users fail to revoke token approvals after using a service, leaving persistent access that can be exploited if the service is later compromised.

Next Steps

After the Layerswap incident, the company promised full refunds plus an additional 10% to affected users — a commendable response that not all projects would match. However, prevention is always better than hoping for reimbursement. Take time this week to audit your own crypto security practices: bookmark your frequently used services, install a wallet security extension, and review your active token approvals on tools like Revoke.cash or Etherscan’s token approval checker. The five minutes you spend on these precautions could save you from becoming the next victim of a domain hijacking attack.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before making any investment decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

25 thoughts on “How to Protect Your Crypto From Domain Hijacking: Lessons From the Layerswap $100K Attack”

  1. cold_storage_mike

    this is why i use a separate hot wallet for every defi interaction. hardware wallet means nothing if you connect it to a hijacked domain

    1. this. 50 wallets drained because someone did not enable proper 2FA on their registrar. $100k lesson for everyone else i guess

  2. godaddy for a crypto project in 2024 is a choice. use a registrar with 2FA and registry lock, this is basic opsec

    1. registry lock costs like $200/year and would have prevented this entire attack. layerswap had six figures in user funds but skipped the most basic domain protection

      1. DNSSEC + registry lock should be mandatory for any project handling user funds. $200 a year to prevent a $100k drain and layerswap skipped it

      2. dnssec_pilled_

        dns_lock_ $200/year registry lock is cheaper than a single drained wallet. layerswap had six figures in user funds and skipped the most basic domain protection. inexcusable

        1. registry_locked_

          dnssec_pilled_ $200 registry lock vs $100K drained. the math is so obvious it hurts. every DeFi frontend should have this as a baseline requirement

      3. dns_lock_now $200 registry lock vs $100K drained should be pinned on every defi teams wall. the fact that layerswap of all projects skipped it is wild

  3. layerswap handled the aftermath pretty well tbh. full reimbursement within 48 hours. but the damage to trust is harder to fix

    1. 50 wallets drained in minutes and it took the Twitter compromise for anyone to notice. monitoring failed at every level here

  4. 50 wallets in minutes because of a GoDaddy account takeover. crypto projects handling user funds need to stop treating domain registration as an afterthought

    1. registrar_watch_

      50 wallets drained in minutes because one Godaddy account had no 2FA enforced. the entire attack surface was the login page

  5. dns_hijack_victim_

    GoDaddy account security in 2024 was still relying on SMS 2FA. one SIM swap and your domain redirects to a phishing site. inexcusable

  6. bridge_user_77

    50 wallets drained in under an hour because nobody bookmarks the actual bridge URL. always verify the domain against a known source before connecting

  7. dns_hijack_victim_ the SIM swap angle is exactly right. GoDaddy was the weak link not Layerswap itself. registry lock would have prevented the whole thing

  8. the attacker bridged stolen funds through deBridge and fixedfloat. the laundering path was faster than layerswap’s response time

    1. Bogdan L. the laundering through deBridge and fixedfloat was faster than the emergency response. that response time gap is the real vulnerability here

      1. transfer_lock_now_

        coldharbor_ transfer locks plus registry lock together would have made this attack basically impossible. two settings, maybe 300 bucks a year total

      2. coldharbor_ the laundering speed vs response time gap is the real issue. by the time anyone noticed the phishing redirect, funds were already through deBridge. monitoring needs to be real-time not twitter-based

  9. registrar_swap_

    Porkbun and Cloudflare both offer registry lock for less than Godaddy charges. the entire crypto industry needs to stop using budget registrars for mission critical infra

  10. the real lesson is nobody checks their registrar security until its too late. every ct thread after a hack says the same thing and nothing changes

    1. defi_insomniac_

      2fa_or_bust the registrar security blindspot is industry-wide. every defi team checks their smart contracts 10 times and leaves their domain on a shared godaddy account with sms 2FA

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$65,004.00+0.2%ETH$1,917.28+0.2%SOL$76.70+1.2%BNB$605.08+0.9%XRP$1.04-0.1%ADA$0.1965-1.2%DOGE$0.0698-0.6%DOT$0.8005-1.5%AVAX$6.49+0.4%LINK$8.24-0.6%UNI$4.01+0.3%ATOM$1.38-0.2%LTC$45.59-0.8%ARB$0.0787+1.0%NEAR$1.61+0.2%FIL$0.7038-0.8%SUI$0.6928+0.7%BTC$65,004.00+0.2%ETH$1,917.28+0.2%SOL$76.70+1.2%BNB$605.08+0.9%XRP$1.04-0.1%ADA$0.1965-1.2%DOGE$0.0698-0.6%DOT$0.8005-1.5%AVAX$6.49+0.4%LINK$8.24-0.6%UNI$4.01+0.3%ATOM$1.38-0.2%LTC$45.59-0.8%ARB$0.0787+1.0%NEAR$1.61+0.2%FIL$0.7038-0.8%SUI$0.6928+0.7%
Scroll to Top