LayerSwap Hack

Reported loss $100K
Ethereum
DNS Hijack

What happened

Layerswap, a cross-chain bridge, had its layerswap.io domain hijacked on March 20, 2024 after an attacker got into the team's GoDaddy account. From about 19:40 UTC visitors were sent to a phishing copy of the site, and about 50 users lost roughly $100,000 in total. The attacker also tried to reset Layerswap's X account.

Layerswap said GoDaddy was slow to respond and that it could not log back in until 23:07 UTC. It then reset the name servers, passwords and 2FA, and the domain was back under its control once DNS propagated at 23:40 UTC. The bridge was fully working again at 00:21 UTC on March 21, and refunds began at 02:50 UTC.

Layerswap promised affected users a full refund plus 10% compensation. It did not publish how the GoDaddy account was breached and said it was waiting for a report from GoDaddy.

How it happened

  1. The attacker gained control of Layerswap's GoDaddy account. Layerswap did not explain how.
  2. The attacker changed the DNS settings for layerswap.io so that visitors reached a phishing site instead of the real bridge.
  3. For about four hours, users who interacted with the fake site lost funds, about $100,000 across roughly 50 users.
  4. Layerswap regained the account at 23:07 UTC, restored its name servers, and turned liquidity and routes back on once DNS had propagated.

Protocol details

Classification Frontend & Infrastructure
Protocol Type DeFi Protocol

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.