📈 Get daily crypto insights that make you smarter about your money

What the Squarespace DNS Attacks Mean for Your Crypto Wallet: A Beginner Guide

On July 12, 2024, the cryptocurrency world watched as some of the most trusted DeFi platforms — including Compound Labs and Pendle — had their websites hijacked by attackers who redirected visitors to phishing pages designed to steal digital assets. The attacks targeted Squarespace, the domain registrar hosting these platforms, exposing a vulnerability that put millions of dollars at risk. If you are new to cryptocurrency, this event might seem alarming, but understanding what happened and how to protect yourself is straightforward. Here is everything you need to know.

The Basics

Every website on the internet has a domain name — like compound.finance or pendle.finance — that tells your browser where to find it. The Domain Name System, or DNS, works like a phone book that matches domain names to the numerical addresses where websites actually live. A DNS hijack happens when someone changes the entries in that phone book so that a legitimate domain name sends you to a fake website instead. In this case, attackers exploited weaknesses in how Squarespace managed domain transfers from Google Domains, allowing them to take control of crypto platform domains and point them to malicious copies.

Why It Matters

When you connect your crypto wallet to a website, you are trusting that the website is genuine. If an attacker has hijacked the domain, the fake site can look identical to the real one but will capture your wallet connection and trick you into approving transactions that drain your funds. With Bitcoin trading around $57,900 and Ethereum at $3,134 at the time, even a small mistake could result in significant losses. This particular attack affected major, well-known platforms — not obscure projects — which makes it especially concerning for everyday users who trust these names.

Getting Started Guide

Protecting yourself from DNS hijacking attacks is easier than you might think. First, always bookmark the official URLs of the crypto platforms you use regularly. Access them only through these saved bookmarks rather than typing the URL or clicking links from emails or social media. Second, before connecting your wallet to any website, check the URL carefully in your browser’s address bar. Look for the correct domain name and ensure there is a padlock icon indicating a secure connection — though be aware that even hijacked sites can have valid SSL certificates. Third, consider using a hardware wallet like a Ledger or Trezor for your significant holdings. Hardware wallets require you to physically press a button on the device to approve transactions, which means even if a fake website tricks you, the transaction details displayed on your hardware wallet’s screen will show the actual destination, giving you a chance to cancel before it is too late.

Common Pitfalls

New crypto users often make several mistakes that leave them vulnerable to these attacks. Many rely on search engines to find crypto platform websites, which can surface phishing links that look legitimate. Some users ignore the URL bar entirely, assuming that if a website looks correct, it must be real. Others store all their crypto in browser-based software wallets, which have no independent screen to verify transaction details. Another common mistake is approving unlimited token spending when interacting with DeFi protocols — even if you trust the protocol, a DNS hijack could redirect you to a malicious contract that drains your tokens.

Next Steps

Start by reviewing all the crypto platforms you currently use and bookmark their official URLs. Consider moving your larger holdings to a hardware wallet if you have not already. When interacting with DeFi protocols, always verify transaction details on your hardware wallet’s screen before confirming. Follow trusted security researchers on social media who often post early warnings about DNS hijacks and other attacks. Stay informed about the platforms you use — many maintain status pages or social media channels where they announce security incidents. The crypto space rewards proactive security practices, and taking these simple steps will significantly reduce your risk exposure.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before making investment decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

21 thoughts on “What the Squarespace DNS Attacks Mean for Your Crypto Wallet: A Beginner Guide”

  1. Compound and Pendle getting DNS hijacked because of a Squarespace migration is wild. your DeFi protocol security is only as strong as your domain registrar

    1. dns_grunt_ literally one compromised registrar and multiple DeFi front-ends redirect to wallet drainers. the single point of failure was not in the protocol itself but in DNS. embarrassing

  2. the google domains to squarespace transfer created a window where 2FA got dropped on some accounts. attackers just found the gap and walked through it

  3. google sold millions of domains to squarespace and nobody thought about the MFA gap during transfer. goes to show your registrar is single point of failure for your entire defi protocol

    1. registrar_void_

      vanya_p the registrar being a single point of failure for an entire DeFi protocol is the real lesson. Compound had billions in TVL protected by a Squarespace login

      1. registrar_void_ Compound had billions in TVL protected by a Squarespace login is the most 2024 crypto sentence possible. protocol security is meaningless if your DNS registrar can be social engineered

  4. compound and pendle dodged a bullet. if the phishing page had a fake approval modal instead of just a login form the damage would have been 9 figures easy

    1. flatwire_ exactly. a DNS hijack into a fake contract interaction page is the nightmare scenario. ENS helps but nobody is typing compound.finance into a resolver field manually

    2. phish_spotter_

      flatwire_ a fake approval modal on the hijacked Compound domain would have drained wallets in minutes. they got lucky it was just a basic phishing page

  5. this is exactly why i use ENS + IPFS for anything serious. DNS is fundamentally broken for high-value targets

    1. ENS is cool until you realize most users will still type compound.finance in their browser. UI layer attacks work because humans are the weak link

  6. good explainer for beginners. the part about Squarespace disabling MFA during migration is wild, how does that pass any security audit

    1. disabling MFA during migration is such an obvious failure mode. every migration guide in existence says enforce MFA, never drop it

      1. dropping MFA during migration is security 101 failure. google to squarespace transfer was a known vector for months before these attacks

  7. compound and pendle are lucky it was just phishing and not contract drains. DNS hijack + fake contract interaction would have been way worse

  8. squarespace inherited millions of google domains accounts and clearly wasnt ready for the security burden. compound and pendle users almost paid for it

  9. the MFA disable during Google to Squarespace migration was reported by security researchers months before the attacks. nobody listened until Compound and Pendle got hit

  10. MFA was disabled for months during the migration and nobody at Squarespace flagged it. a registrar handling DeFi domains needs SOC2 audits not Google Domains import scripts

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$65,230.00+0.5%ETH$1,925.95+0.3%SOL$76.93+0.8%BNB$604.26+0.3%XRP$1.04+0.0%ADA$0.1977-0.1%DOGE$0.0700-0.1%DOT$0.80980.0%AVAX$6.53+0.8%LINK$8.22-1.2%UNI$4.05+2.0%ATOM$1.38+0.2%LTC$45.51-1.5%ARB$0.0801+3.0%NEAR$1.66+2.1%FIL$0.7063-0.7%SUI$0.6951+0.3%BTC$65,230.00+0.5%ETH$1,925.95+0.3%SOL$76.93+0.8%BNB$604.26+0.3%XRP$1.04+0.0%ADA$0.1977-0.1%DOGE$0.0700-0.1%DOT$0.80980.0%AVAX$6.53+0.8%LINK$8.22-1.2%UNI$4.05+2.0%ATOM$1.38+0.2%LTC$45.51-1.5%ARB$0.0801+3.0%NEAR$1.66+2.1%FIL$0.7063-0.7%SUI$0.6951+0.3%
Scroll to Top