LayerSwap Hack
What happened
Layerswap, a cross-chain bridge, had its layerswap.io domain hijacked on March 20, 2024 after an attacker got into the team's GoDaddy account. From about 19:40 UTC visitors were sent to a phishing copy of the site, and about 50 users lost roughly $100,000 in total. The attacker also tried to reset Layerswap's X account.
Layerswap said GoDaddy was slow to respond and that it could not log back in until 23:07 UTC. It then reset the name servers, passwords and 2FA, and the domain was back under its control once DNS propagated at 23:40 UTC. The bridge was fully working again at 00:21 UTC on March 21, and refunds began at 02:50 UTC.
Layerswap promised affected users a full refund plus 10% compensation. It did not publish how the GoDaddy account was breached and said it was waiting for a report from GoDaddy.
How it happened
- The attacker gained control of Layerswap's GoDaddy account. Layerswap did not explain how.
- The attacker changed the DNS settings for
layerswap.ioso that visitors reached a phishing site instead of the real bridge. - For about four hours, users who interacted with the fake site lost funds, about $100,000 across roughly 50 users.
- Layerswap regained the account at 23:07 UTC, restored its name servers, and turned liquidity and routes back on once DNS had propagated.
Protocol details
Evidence
- report Layerswap March 20 incident (Layerswap on X, thread start) x.com
- report Layerswap March 20 incident timeline (Layerswap on X) x.com
- analysis DeFiLlama defillama.com
- analysis Layerswap domain hijack ends, $100k stolen funds to be refunded (crypto.news) crypto.news
- analysis Layerswap hack: $100k lost, users to be fully refunded (CoinJournal) coinjournal.net
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.