Balancer blames ‘social engineering attack’ on DNS provider for website hijack

Blockchain security firms SlowMist and CertiK also believe the crypto wallet drainer Angel Drainer was involved in the estimated $238,000 exploit.

Balancer Blames ‘social Engineering Attack’ On Dns Provider For Website Hijack_65b96d1f9a8d0.jpeg

The team behind Balancer, an Ethereum-based automated market maker, believes a social engineering attack on its DNS service provider was what led to its website’s frontend being compromised on Sept. 19, leading to an estimated $238,000 in crypto stolen.

“After investigation, it is clear that this was a social engineering attack on EuroDNS, the domain registrar used for .fi TLDs,” the firm explained in a Sept. 20 X post.

Approximately 8 hours after the first warning of the attack, Balancer said its decentralized autonomous organization (DAO) was actively addressing the DNS attack and was working to recover the Balancer UI.

At 5:45 pm UTC on Sept. 20, Balancer said it was successful in securing the domain and bringing it back under the control of Balancer DAO. It also confirmed its subdomains “app.balancer.fi” and other “balancer.fi” are safe to use again.

balancer blames social engineering attack on dns provider for website hijack 65b96d1f9d194

However, it suggested any other projects using the same top-level domain should consider moving to a more secure registrar.

EuroDNS is a Luxembourg-based domain name registrar and DNS service provider. Cointelegraph has reached out to EuroDNS for comment.

Angel Drainer involved

Blockchain security firms SlowMist and CertiK reported that the attacker employed Angel Drainer phishing contracts.

SlowMist said the exploiters attacked the Balancer’s website via Border Gateway Protocol hijacking — a process where hackers take control of IP addresses by corrupting internet routing tables.

The hackers then induced users to “approve” and transfer funds via the “transferFrom” function to the Balancer exploiter, it explained.

Related: Binance CEO refutes report on $250M loan to BAM Management

The hacker, whom SlowMist believes may be related to Russia, has already bridged some of the stolen Ether (ETH) to Bitcoin (BTC) addresses via THORChain before eventually being bridging the ETH back to Ethereum, blockchain security firm SlowMist explained on Sept. 20.

SlowMist stated in an earlier post that the hacker transferred about 15 wrapped-Ether (wETH.e) on the Avalanche blockchain.

balancer blames social engineering attack on dns provider for website hijack 65b96d20339ec

Meanwhile, despite Balancer confirming its subdomains, balancer.fi to now be safe, visits to the website still shows “Deceptive site ahead” warning when attempting to access the Balancer’s website.

Balancer’s website as of Sept. 20 at 10:22 pm UTC. Source: Balancer.

AZC News reached out to Balancer to confirm the amount of funds lost but did not receive an immediate response.

(100 votes)

5.0/5

(100 votes)

Latest

Government Set To Reopen After 7 Weeks Of Shutdown 2

News | Editor Choice | Policy & Regulations

Government Set to Reopen After 7 Weeks of Shutdown

After more than seven weeks of paralysis due to the budget crisis, the U.S. government is set to reopen as the House of Representatives passes a historic spending bill, ready for President Donald Trump’s signature.

China Accuses The U.s. Of Masterminding A $13 Billion Bitcoin Theft

News | Bitcoin | Editor Choice

China Accuses the U.S. of Masterminding a $13 Billion Bitcoin Theft

China has sent shockwaves across global markets after accusing the U.S. of orchestrating a $13 billion Bitcoin theft, turning the world’s largest cryptocurrency into the latest flashpoint in the tech rivalry between the two superpowers.

Deposit 15 Usdt And Get 15 Usdt On Bingx

Airdrops | Editor Choice

Deposit 15 USDT and get 15 USDT on BingX

To welcome new traders and thank our loyal users, BingX is launching a special deposit bonus campaign with total rewards of up to 3,000 USDT.

James Wynn Goes “all In” On Shorting Bitcoin After 12 Liquidations

News | Bitcoin | Editor Choice

James Wynn Goes “All-In” on Shorting Bitcoin After 12 Liquidations

High-leverage trader James Wynn has gone “all-in” betting on Bitcoin dropping below $92,000, despite being liquidated 12 times in just 12 hours, leaving the crypto community closely watching his high-risk moves.

Trump Considers Giving Americans $2,000 From Tariff Revenues

News | Editor Choice | Policy & Regulations

Trump Considers Giving Americans $2,000 from Tariff Revenues

President Donald Trump has shaken up U.S. politics once again, announcing a plan to hand out $2,000 per American from tariff revenues—an audacious move seen as his latest bid to capture voter enthusiasm ahead of the election.

Screenshot 2025 10 20 091338