Aerodrome V1 Hack

Reported loss $700K
Ethereum Optimism
DNS Hijack

What happened

Aerodrome is the main trading and liquidity marketplace on Base, and its sister exchange Velodrome runs on Optimism. On November 21, 2025, attackers hijacked the DNS for both exchanges' centralized domains (.finance and .box) and sent visitors to phishing copies of the real sites. Users who connected a wallet and signed transactions there had funds drained. The team's post-mortem puts user losses at about $700,000. Early community estimates had said more than $1 million.

According to the post-mortem, the root cause was a compromised insider at the registrar NameSilo. The attacker got around the multisig controls in the 3DNS system, removed DNSSEC from both domains and pointed them at malicious pages. The smart contracts were not affected, and the decentralized ENS-based mirrors stayed safe.

Security partners including Blockaid, SEAL and 0xGroomLake flagged malicious transactions within minutes and pushed wallet warnings. The team said mitigation was complete in under four hours, that it was moving the domains to new registrars, and that it planned a grant program for affected users. It was the second DNS hijack of these frontends, after one in November 2023.

How it happened

  1. A compromised insider at NameSilo got around the multisig controls on the 3DNS-managed domains and removed DNSSEC from Aerodrome's and Velodrome's .finance and .box domains.
  2. The DNS records were changed to point at attacker-hosted copies of the real frontends.
  3. Visitors to the usual URLs saw a familiar interface. After they connected a wallet, the fake site showed transactions that looked harmless, reportedly displaying just the number "1", followed by unlimited token approval requests for assets such as ETH, WETH and USDC.
  4. The attacker used the approvals and signatures to drain the victims' wallets. The protocol contracts were never touched.
  5. The team sent users to the ENS mirrors, and security partners pushed wallet warnings against the malicious transactions.

Protocol details

Classification Frontend & Infrastructure
Protocol Type DEX
Implementation language Solidity
Protocol links Website @aerodromefi

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.