DNS provider EasyDNS confirmed responsibility for the eth.limo domain hijack on April 17-18, marking its first successful social engineering attack in 28 years after an attacker impersonated an eth.limo team member to gain account access. The attacker switched eth.limo's nameservers twice between 2:23 a.m. and 3:57 a.m. EDT before EasyDNS restored legitimate access at 7:49 a.m. However, DNSSEC protections prevented any actual traffic redirection because the attacker never obtained eth.limo's cryptographic signing keys, causing resolvers to return SERVFAIL errors instead of malicious responses. The incident affects a service providing browser access to roughly 2 million ENS domains and follows similar DNS hijacks at Aerodrome, Velodrome, Steakhouse Financial, and Neutrl that collectively drained over $700,000 from users. EasyDNS will migrate eth.limo to Domainsure, an enterprise service without account recovery mechanisms, while Vitalik Buterin advocates for reducing Ethereum's dependence on centralized DNS by 2026.
Story comments
Loading comments…