Kelp DAO security incident analysis: Attackers convinced GoDaddy customer support by impersonating the Kelp team and bypassed 2-FA verification

2024/07/29 16:34

Odaily News On July 29, the liquidity staking protocol Kelp DAO reviewed previous security incidents: At 22:30 on July 22, Kelps dApp began to show malicious wallet activity transactions in an attempt to steal user funds. The Kelp team responded immediately, locked the domain name server, restored ownership access, and resolved the problem. The attacker successfully convinced GoDaddys customer support to bypass 2-FA by impersonating the Kelp team. The Kelp team is taking preventive measures, including transferring to another domain name registrar and strengthening alerts for abnormal UI behavior. A small number of users have reported losing funds due to UI attacks, and the Kelp team is providing support.

原文链接
Latest news
09:42
Digital currency concept stocks were active at the beginning of the session, with Eastcom Peace hitting the daily limit
09:38
Bitdeer mined 65 BTC last week, and its total Bitcoin holdings exceeded 1,600
09:33
A whale deposited 400.1 BTC into Binance, worth $47.23 million
09:30
星球早讯
09:20
Bithumb plans to suspend MultiverseX (EGLD) deposits and withdrawals on July 24
Recommended Reading