Convex Finance Hack
What happened
A DNS attack was conducted on Convex Finance. The hacker managed to create a contract with a similar address, prompting users to sign approval without noticing the substitution.
Convex Finance, a protocol offering boosted rewards for Curve liquidity providers and stakers.
Hackers changed the original website address with the original contract to a copy of the website with a fake contract address.
Original contract address: 0xF403C135…8AAE31
Malicious contract address: 0xF403a2c1…87AE31.
The hackers managed to recreate the address of the contract, very similar to the address of the Convex contract, and the users did not notice the substitution, paying attention to the first 4 or last 4 characters thinking there is no problem and signed the malicious approval transaction. In total, 15,968 $CVXCRV and 433 $CRV were lost.
Scammer address: https://etherscan.io/address/0xb7326148…5af9aa
Malicious contract address: https://etherscan.io/address/0xF403a2c1…87AE31
Accounts that approved malicious contract:
Protocol details
Security review history
- MixBytes View report
Evidence
- report Report thedefiant.io
- report Report convexfinance.medium.com
- analysis Web Archive web.archive.org
- analysis DeFiLlama defillama.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.