Grafa
Eth.limo hack traced to social engineering breach
Eth.limo hack traced to social engineering breach

Eth.limo hack traced to social engineering breach

Share

Ethereum Name Service gateway eth.limo said its domain hijack was caused by a social engineering attack targeting its domain provider EasyDNS, allowing an attacker to gain account access and alter DNS records.

The attacker impersonated a team member to trigger an account recovery process, redirecting the domain’s name server records before the breach was identified and mitigated.

“We screwed up and we own it,”

Said Mark Jeftovic, confirming the incident marked the first successful social engineering attack against an EasyDNS client.

The hijack briefly raised concerns as eth.limo acts as a Web2 gateway to around two million .eth domains, meaning compromised access could have redirected users to malicious websites.

However, both eth.limo and EasyDNS said Domain Name System Security Extensions (DNSSEC) prevented further damage by blocking invalid cryptographic signatures, limiting the attack’s impact.

Ethereum co-founder Vitalik Buterin had earlier warned users to avoid affected services until the issue was resolved.

EasyDNS said it is implementing stronger security measures, including migrating eth.limo to a more secure system without account recovery features, as crypto-related domain hijacks continue to rise.

At the time of reporting, Ethereum price was $2,284.30.

Perguntas frequentes

Conecte-se conosco

A Grafa não é um consultor financeiro. Você deve buscar aconselhamento independente, jurídico, financeiro, tributário ou de outra natureza que se relacione às suas circunstâncias únicas.

A Grafa não se responsabiliza por qualquer perda causada, seja por negligência ou de outra forma, decorrente do uso ou da confiança nas informações fornecidas direta ou indiretamente pelo uso desta plataforma.