Convex Finance Hack

Reported loss $14K
ethereum
Other

What happened

A DNS attack was conducted on Convex Finance. The hacker managed to create a contract with a similar address, prompting users to sign approval without noticing the substitution.

Convex Finance, a protocol offering boosted rewards for Curve liquidity providers and stakers.

Hackers changed the original website address with the original contract to a copy of the website with a fake contract address.

Original contract address: 0xF403C135…8AAE31

Malicious contract address: 0xF403a2c1…87AE31.

The hackers managed to recreate the address of the contract, very similar to the address of the Convex contract, and the users did not notice the substitution, paying attention to the first 4 or last 4 characters thinking there is no problem and signed the malicious approval transaction. In total, 15,968 $CVXCRV and 433 $CRV were lost.

Scammer address: https://etherscan.io/address/0xb7326148…5af9aa

Malicious contract address: https://etherscan.io/address/0xF403a2c1…87AE31

Accounts that approved malicious contract:

  1. Address
  2. Address
  3. Address
  4. Address
  5. Address

Protocol details

Classification Yield Aggregator / Frontend & Infrastructure
Protocol Type Yield
Affected asset / contract CVX
Protocol links Website @ConvexFinance

Security review history

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.