The DeFi protocol Aerodrome recently suffered a major setback. Their centralized domain name was hit by a DNS attack, and what’s even more outrageous is that the attack came from an insider at NameSilo, who directly bypassed 3DNS’s multisig security mechanism and redirected users to a phishing page.



This operation ultimately caused users to lose around $700,000. Once again, this incident proves that decentralized applications still rely on centralized domain service providers, which is a significant vulnerability. In the security architecture of on-chain dApps, domain-level protection clearly needs a much stronger solution.

When accessing DeFi protocols, users should always double-check the website and contract addresses—a little extra caution can be a lifesaver.
AERO4.06%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 9
  • Repost
  • Share
Comment
Add a comment
Add a comment
LiquidationWatcher
· 2025-11-26 19:46
Once again, it's an insider causing trouble, NameSilo has fallen directly, and multi-signature is practically useless.

---

700,000 just disappeared like that; the domain service provider is indeed a dead end.

---

Speaking of which, one must be vigilant; phishing sites are hard to defend against.

---

The internal personnel committing crimes is the most ridiculous; all the multi-signature talk is pointless.

---

Decentralization has been shouted for so long, but it's stuck on traditional infrastructure like domains.

---

If this guy had checked the address bar, he might not have lost 700,000.

---

NameSilo's reputation has completely collapsed this time; it feels like no one will trust them anymore.

---

Checking URLs is actually a classic method that can really save lives, ironic.

---

Insiders are even more fierce than hackers; it's impossible to guard against them.

---

Another Web3 security disaster scene; how are there still so many people stepping into the pit?
View OriginalReply0
BlockchainDecoder
· 2025-11-26 03:04
From a technical perspective, this issue reflects not just a single vulnerability but a structural defect in the entire DNS governance system. It is worth noting that the multi-signature mechanism of 3DNS was bypassed, indicating that internal permission management is much looser than we imagined.

Based on the data analysis of previous domain hijacking cases, the reason why the success rate of such attacks is so high fundamentally lies in the excessive reliance of on-chain applications on centralized infrastructure. The fact that NameSilo employees directly overstepped their authority reveals a deeper issue—single point of failure in access control.

It is recommended that on-chain projects seriously study the ENS solution. Although it is not perfect, it at least moves domain resolution authority one step onto the chain. A loss of $700,000 is indeed heart-wrenching, but in the long run, promoting the standardization upgrade of the industry in terms of domain security makes this cost worthwhile.
View OriginalReply0
AirdropFreedom
· 2025-11-25 19:20
Another insider? NameSilo is really pumping too much, the multi-signature is essentially useless.

---

700,000 gone... this is the cost of trusting centralization, so frustrating.

---

They promised decentralization, but it's still stuck at DNS? Laughing to death, you can't escape the trap of centralization at all.

---

Damn, this operation, internal staff acting directly? What was the security audit doing?

---

In terms of domains, this is indeed the Achilles' heel of Decentralized Finance, we need to find a way to go on-chain.

---

Can't even save bookmarks? Have to verify the contract address every time, so annoying.

---

Aerodrome stumbled, other projects should reflect on this, everyone should check their domain security.

---

Multi-signature was breached by an insider, now it's defenseless.

---

No wonder pros say DeFi is still in its early stages, there are still a bunch of vulnerabilities.

---

The key issue is how users can distinguish between real and fake websites? Isn't this just letting newbies lose money?
View OriginalReply0
PretendingToReadDocs
· 2025-11-24 06:37
Is it done by an insider again? How can we play like this, the domain layer can't defend against it at all.
View OriginalReply0
BetterLuckyThanSmart
· 2025-11-24 06:36
The domain name issue is indeed a huge pain point, insiders are the most terrifying.

---

700,000 is gone, I just want to ask who is going to compensate?

---

With both DNS and multi-signature, it still boils down to the fault of centralization.

---

Verifying URLs is an outdated trick; we really need to think of ways to block it at the source.

---

Insiders at NameSilo have completely broken through defenses; this level of trust... never mind.

---

It’s always like this, dApps shout about Decentralization, but in the end, domain names still rely on centralized guardians.

---

It’s hard to defend against; phishing pages are so well made that even I can’t tell the difference.

---

If triple DNS and multi-signature can't prevent insiders, then what’s the point of multi-signature?

---

This shows that there are pitfalls everywhere in the ecosystem; we have to keep our eyes wide open.

---

Centralized domain names are the Achilles' heel of Web3; whoever solves it wins big.
View OriginalReply0
AllInDaddy
· 2025-11-24 06:33
NameSilo insiders directly breached defenses, this wave is really outrageous

---

$700,000 just disappeared like that, trust issues are the most fatal

---

I've said it countless times, don't click on strange links, but some people just don't listen

---

The security vulnerabilities in the domain name area really need to be taken seriously, otherwise decentralization is pointless

---

Internal personnel committing crimes? That's too much, who can defend against that

---

If multi-signature can be bypassed, then security measures are essentially useless

---

Phishing pages are so easy to fall for, users need to be more vigilant

---

This incident shows that dApps still need to be optimized, we can't just rely on domain names for sustenance
View OriginalReply0
StopLossMaster
· 2025-11-24 06:33
It's another insider causing trouble; this level of security is really frustrating.

---

An insider at NameSilo directly bypassed the multi-signature... what happened to Decentralization?

---

700,000 just disappeared like that; the domain name space is indeed a dead spot.

---

I just want to know, what is the point of multi-signature if it can be bypassed internally?

---

I've said it before, the joke is that decentralized applications cannot exist without centralized infrastructure.

---

Checking the URL before accessing DeFi is too low-level; the technical solution is fundamental.

---

This incident has completely damaged NameSilo's reputation, and the trust in the whole industry has declined.

---

Centralized domain names are the cancer of web3; when can this be solved on-chain?

---

700,000 USD, bro; this phishing attempt is really harsh.

---

Insiders are scarier than Hackers; multi-signature is practically useless.
View OriginalReply0
SelfMadeRuggee
· 2025-11-24 06:15
Is it another insider doing this? NameSilo has really given the industry a lesson this time, $700,000 just vanished...

---

The domain name aspect is indeed the Achilles' heel of Web3, what’s the point of decentralization?

---

Where’s the multi-signature we talked about? In the end, it still can’t prevent internal personnel, it’s really a human issue.

---

Now even DNS isn’t safe, I truly don’t know what to trust anymore, maybe building my own Node is more secure.

---

That’s why I have to manually verify contract addresses every time, it’s a hassle but at least it gives me peace of mind.

---

Ngl, this incident really broke my defenses, NameSilo's reputation is completely tarnished now.

---

$700,000... Someone has gone bankrupt because of this, just thinking about it makes me feel awful.

---

So we still have to use ENS, a truly decentralized solution, but why is it so troublesome to use?

---

Insiders are even more ruthless than hackers, multi-signature is practically useless in the face of internal corruption.
View OriginalReply0
MainnetDelayedAgain
· 2025-11-24 06:15
According to the database, this DNS crash of Aerodrome has happened several times already... How long has it been since the last similar security incident? It is suggested to be included in the Guinness World Records.

Regarding the insider at NameSilo, 700,000 USD just disappeared like that, really interesting. Centralization has always been a source of concern.
View OriginalReply0
View More