PancakeSwap / Cream Finance Hack
What happened
On March 15, 2021, attackers hijacked the DNS of two DeFi sites, PancakeSwap and Cream Finance. A source who tipped off The Record said the DNS records for both sites were changed within a minute of each other, pointing to a single attacker. Visitors to the real domains were sent to fake versions that showed a pop-up asking for their wallet's seed phrase. Anyone who entered it would hand the attacker full control of that wallet.
Cream warned users on X not to enter their seed phrase and said it would never ask for one; PancakeSwap told users not to use its site until it could confirm what had happened. Both later confirmed that the attackers had got into their GoDaddy accounts, where their DNS was managed. PancakeSwap regained control of its DNS by about 17:30 UTC the same day, while Cream was still working on it. No total loss figure has been published.
How it happened
- The attackers gained access to the GoDaddy accounts that managed DNS for PancakeSwap and Cream Finance.
- They changed the DNS records so the projects' domains pointed to attacker-controlled servers.
- Those servers showed copies of the sites with a pop-up asking visitors for their 12-word seed phrase.
- Seed phrases entered there would let the attackers take everything in the victims' wallets.
- The projects warned users, then restored their DNS records.
Protocol details
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.