Skip to content
Active Currencies: 17,411
Market Cap: $2.235T
Bitcoin Dominance: 56.26%
24h Market Cap Change: $-1.10

Was Convex Finance targeted in the latest spoofing exploit

Amid the broader market downturn, 24 June was a rather unforgettable day for the crypto community. After the Harmony Bridge was attacked for $100 million Convex Finance urged its users to be diligent in checking the addresses for contract approvals. Reportedly, the website of Convex Finance was hijacked earlier on 24 June.

“Need a hand here”

Curve’s Convex Finance is a DeFi protocol built to reward liquidity providers. It also provides additional yields to those who stake Curve Finance’s native token, CRV. The protocol suffered a DNS (Domain Name System) hijacking.

It was targeted in the latest spoofing exploit. The hijacking prompted users to accept and approve malicious contracts for some interactions on the site. In fact, the attack was confirmed by the Convex team via the following tweet,

The Convex team confirmed the five addresses that approved these “malicious contracts.” They asked the owners of the following addresses to report via Twitter or Discord channels at the earliest. The accounts listed in the tweet were,

  • 0x496e53c32a69a79a82ed85d2913010dd2f9d1b4f
  • 0x4ffc5f22770ab6046c8d66dabae3a9cd1e7a03e7
  • 0x5b186c93a50d3cb435fe2933427d36e6dc688e4b
  • 0x624301090700ea1e3c5b5224f89adfae405412c1
  • 0x92557b6ffa116b53cf2c3bc1d6d33f78d97ed4c9

While the investigation is still going on, no funds are affected yet on the verified contracts. In the wake of this alarming issue, the Convex team then created an alternate domain as a precautionary measure for users. Until the post-mortem of the attack, the sites mentioned below are being suggested for safe passage into the protocol.

Not the first one

The attack on Convex Finance comes on a day when $100 million in ETH was stolen from the Harmony Bridge hack. It is the latest cross-chain bridge to suffer a security breach. This comes after Axie Infinity’s Ronin Bridge suffered a $600 million hack earlier in March.

Disclaimer: AMBCrypto's content is meant to be informational in nature and should not be interpreted as investment advice. Trading, buying or selling cryptocurrencies should be considered a high-risk investment and every reader is advised to do their own research before making any decisions.

Kanav is a journalist at AMBCrypto. He has a Masters in Media and International Conflict and is interested in areas of digital society, crypto developments in the political sphere and the socio-cultural impact of a crypto-society.

AMBCrypto was founded in 2018 with a mission to simplify and bring the latest blockchain and cryptocurrency news to our readers. We have quickly grown into the digital news source for an emerging generation of cryptocurrency enthusiasts, reaching more than a million readers on a monthly basis, across the globe.