Kelp DAO security incident analysis: Attackers convinced GoDaddy customer support by impersonating the Kelp team and bypassed 2-FA verification

2024/07/29 16:34

Odaily News On July 29, the liquidity staking protocol Kelp DAO reviewed previous security incidents: At 22:30 on July 22, Kelps dApp began to show malicious wallet activity transactions in an attempt to steal user funds. The Kelp team responded immediately, locked the domain name server, restored ownership access, and resolved the problem. The attacker successfully convinced GoDaddys customer support to bypass 2-FA by impersonating the Kelp team. The Kelp team is taking preventive measures, including transferring to another domain name registrar and strengthening alerts for abnormal UI behavior. A small number of users have reported losing funds due to UI attacks, and the Kelp team is providing support.

原文链接
Latest news
00:51
BitMart completes ETH L2 network hard fork upgrade, deposits and withdrawals have been restored
00:41
The whale deposited $10 million USDC into HyperLiquid and opened a short position in BTC, SOL and ETH with 5x leverage
00:14
Coinbase Q1 earnings report falls short of expectations, Wall Street receives mixed reviews after completing $2.9 billion acquisition of Deribit
00:09
Solana Chain SOL Short Liquidation Volume Exceeds Centralized Exchanges, Reaching $47 Million
00:00
Doodles: Some airdrop wallets have problems, and repairs have been initiated
Recommended Reading