Namecheap DNS Hijack
Check if your address is affected.
In late June 2022, attackers took over the DNS records of several DeFi websites, including Convex Finance, Ribbon Finance, DeFi Saver and Allbridge. DNS records tell your browser where to find a website, so by changing them the attackers could send visitors to a malicious copy of the real site. All of the affected projects had registered their domains with Namecheap, and Namecheap's CEO later said the changes were made by a customer support agent who had been hacked or otherwise compromised.
The fake sites looked just like the real ones, but some buttons asked users to approve attacker contracts instead of the real protocol contracts. Many of these were deployed at addresses that started and ended with the same characters as the real contracts, making them hard to spot at a glance. Over $550k was stolen in total, including about $350k in WBTC from Ribbon Finance users. The teams quickly regained control of their websites, and Convex offered to compensate its affected users from its treasury once they had revoked the malicious approvals.
The malicious approvals point to contracts controlled by the attackers, so they stay dangerous for as long as they exist, even though the affected websites are safe again. If you used Convex, Ribbon, DeFi Saver or Allbridge in late June 2022, check your approvals and revoke any that point to the addresses listed here. More generally, always compare the full contract address you are approving, not just its first and last few characters.
Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.
Next time, revoke it automatically
Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.
See how Auto-Revoking works →