On February 16, 2026, blockchain security firm Blockaid flagged simultaneous front-end attacks on two DeFi protocols — real-world asset tokenization platform OpenEden and lending protocol Curvance. Just one week earlier, $2 billion onchain asset manager Maple Finance suffered an identical comprom...
"Preventative measures were taken before any loss of funds occurred." — Curvance Team, in response to their front-end compromise (February 16, 2026)
On February 16, 2026, blockchain security firm Blockaid flagged simultaneous front-end attacks on two DeFi protocols — real-world asset tokenization platform OpenEden and lending protocol Curvance. Just one week earlier, $2 billion onchain asset manager Maple Finance suffered an identical compromise. All three attacks were attributed to the same weapon: the AngelFerno wallet drainer, a "scam-as-a-service" toolkit that has quietly become one of the most dangerous threats in decentralized finance.
The attacks share a troubling pattern. In each case, the underlying smart contracts were never breached. User funds in the protocols remained safe. Instead, attackers targeted the front-end — the website through which users interact with the protocol — injecting malicious code designed to trick users into signing transactions that drain their wallets. It is the digital equivalent of replacing a bank's ATM interface with a counterfeit that steals card details while the vault inside remains untouched.
This front-end attack vector has been escalating since mid-2024, and yet the DeFi industry has made almost no structural progress in addressing it. The implications are severe: as institutions deploy billions into onchain credit markets and tokenized assets, the front door to these protocols remains the weakest link in the security chain.
Three protocols were hit in rapid succession:
Maple Finance (February 9): The $2 billion onchain asset manager's website was compromised, with malicious code inserted to generate fraudulent approval transactions. The team regained control and confirmed "smart contracts and funds have remained safe and unaffected."
OpenEden (February 16): Blockaid detected a front-end attack on the RWA tokenization platform, warning users to avoid both openeden.com and portal.openeden.com "as it can cause you to lose your wallet's assets." The attack was attributed to the AngelFerno drainer.
Curvance (February 16): An Ethereum Security Alliance member flagged a domain compromise on the lending platform's website. A malicious approvals transaction was generated by the AngelFerno drainer. Curvance stated preventative measures were enacted before any funds were lost.
Blockaid issued an immediate advisory: "refrain from signing transactions and avoid interactions with the dApp until the issue is resolved."
In all three cases, the smart contracts — the actual financial infrastructure — were never compromised. The attack surface was exclusively the front-end, the traditional web layer sitting between users and the blockchain.
A front-end attack exploits the gap between DeFi's decentralized backend and its centralized presentation layer. The attack chain typically works as follows:
Step 1: Domain or DNS Compromise. The attacker gains access to the protocol's domain registrar account or DNS provider. This can be achieved through credential theft, social engineering, or exploiting weak security configurations at the hosting provider.
Step 2: Code Injection. Once in control of the domain, the attacker modifies the front-end code served to users. The website looks identical to the legitimate version.
Step 3: Malicious Transaction Generation. When users connect their wallets and attempt to interact with the protocol, the compromised front-end generates fraudulent transactions — typically token approval or transfer transactions — that, if signed, send funds directly to the attacker's wallet.
Step 4: Wallet Drainer Execution. Tools like AngelFerno analyze the contents of a connected wallet and dynamically generate the most profitable malicious transaction. If the wallet contains stablecoins, it requests an unlimited approval. If it contains NFTs, it requests a transfer. The drainer is optimized for maximum extraction.
The critical insight: the blockchain layer is never touched. The attack operates entirely in the traditional web infrastructure stack — DNS records, web hosting, and JavaScript execution. DeFi protocols have invested hundreds of millions in smart contract audits while leaving the front door protected by the same security model as a WordPress blog.
AngelFerno is not an isolated threat actor. It is a product of a mature, professionalized criminal ecosystem known as "Drainer-as-a-Service" (DaaS).
The business model is straightforward: DaaS operators develop sophisticated wallet-draining scripts and license them to downstream attackers — phishing operators, SIM swappers, and social engineers — in exchange for a 20-30% cut of stolen funds. The operator handles the technology; the affiliates handle the distribution.
The market has consolidated. In 2024, the team behind the notorious Inferno Drainer — which had stolen over $80 million — transferred its entire toolkit and infrastructure to Angel Drainer. This merger created a dominant player with expanded capabilities. The combined operation, which evolved into AngelFerno (also tracked as AngelX), reportedly deployed over 300 malicious decentralized applications in its first months of operation.
The financial scale is significant. Wallet drainer scams collectively stole $494 million in 2024 from over 300,000 victims, according to security researchers. While 2025 saw an 83% decline in wallet drainer losses to $83.85 million (with victims falling to 106,000), the shift toward front-end attacks on major protocols suggests the operators are evolving from retail phishing toward higher-value institutional targets.
This is no longer petty theft. It is industrialized fraud with professional tooling, revenue-sharing agreements, and active R&D.
The February 2026 attacks are not anomalous. They are the latest in an escalating series that the DeFi industry has repeatedly failed to address structurally:
July 2024 — The Squarespace Catastrophe. When Google sold its domain business to Squarespace, the forced migration removed two-factor authentication from domain accounts. Attackers exploited this vulnerability to hijack DNS records for over 120 DeFi protocols, including Compound Finance, Celer Network, and Pendle Finance. Compound's website was redirected to a page equipped with a wallet drainer.
November 2025 — Aerodrome Finance. The largest DEX on Base suffered a DNS hijack that redirected users to a phishing site, resulting in estimated losses exceeding $1 million.
October 2025 — Multi-Protocol Wave. Garden Finance, Typus Finance, and Abracadabra collectively lost $16.2 million from DNS-related breaches and associated oracle manipulation.
February 2026 — OpenEden, Curvance, Maple Finance. Three protocols hit in eight days by the same wallet drainer toolkit.
According to security research aggregated by Three Sigma, compromised front-ends were the most frequent and costly attack vector in DeFi between 2023 and 2025. The cumulative damage across the broader category of off-chain exploitation (which includes DNS hijacking, front-end compromise, and social engineering) runs into the billions.
Yet the response from the industry has been largely reactive: warn users, take down the compromised site, confirm smart contracts are safe, move on. The underlying vulnerability — centralized hosting and DNS infrastructure — remains unaddressed by the vast majority of protocols.
The timing of this attack wave is particularly concerning given the current trajectory of institutional DeFi adoption. Maple Finance is not a niche yield farm. It is an institutional lending platform managing $2 billion in onchain assets. OpenEden tokenizes real-world assets for sophisticated investors. These are exactly the protocols that institutional capital — from Apollo, BlackRock, and other traditional asset managers — is flowing toward.
Consider the operational risk: a pension fund allocating capital through a DeFi lending protocol now faces the possibility that the protocol's website could be compromised at any time, generating malicious transactions that, if signed by an authorized signer, could drain the fund's onchain position. The smart contract audit is irrelevant. The $500,000 bug bounty program is irrelevant. The attack bypasses all of it.
According to Chainalysis, total crypto theft reached $3.4 billion in 2025, with the top three incidents accounting for 69% of all losses. Individual wallet compromises surged to 158,000 incidents affecting 80,000 unique victims. North Korean state-sponsored hackers alone stole $2.02 billion.
For institutions evaluating DeFi allocation, the front-end attack vector introduces a category of risk that does not exist in traditional finance: the possibility that the interface to your financial infrastructure could be silently replaced by a weapon targeting your assets.
The technical solutions exist. The industry simply has not adopted them at scale.
IPFS-Based Hosting. The InterPlanetary File System assigns cryptographic content identifiers (CIDs) to every file. Any modification to a single byte of front-end code produces a completely different CID, making tampering instantly detectable. Protocols deploying their front-ends on IPFS eliminate the DNS hijacking vector entirely.
ENS and Decentralized Domain Resolution. Ethereum Name Service (ENS) and similar systems can point directly to IPFS CIDs instead of traditional IP addresses, removing the centralized DNS layer from the trust chain.
Local-First Front-Ends. Liquity has pioneered a model where users install front-end source code directly on their devices, referencing source locations via GitHub or IPFS hashes. This eliminates the need for any public-facing web server.
Transaction Simulation and Verification. Security providers like Blockaid now scan over 15 million sites daily and detect over 500 new malicious dApps, providing real-time alerts before users sign transactions. Wallet-level protections — including MetaMask's compromised-site warnings and Blockaid's integration with TRON, announced in January 2026 — add a critical last line of defense.
The tradeoffs are real: IPFS access can be slower than CDN-served websites, updates require generating new CIDs, and decentralized hosting introduces operational complexity. But the alternative — continuing to serve billion-dollar protocols through infrastructure with the security model of a 2005 web application — is indefensible.
Three major DeFi protocols — Maple Finance, OpenEden, and Curvance — were hit by front-end attacks in a single week in February 2026, all attributed to the AngelFerno wallet drainer toolkit. No user funds were lost due to rapid detection and response.
Front-end attacks exploit the centralized web layer (DNS, hosting, JavaScript) while leaving smart contracts untouched. This makes traditional DeFi security measures — audits, bug bounties, formal verification — irrelevant to this attack vector.
The Drainer-as-a-Service economy has matured into a professionalized industry with revenue-sharing, mergers and acquisitions (Inferno → Angel Drainer → AngelFerno), and active product development targeting institutional-grade protocols.
Institutional DeFi adoption amplifies the risk. As Apollo, BlackRock, and other asset managers deploy capital through onchain protocols, the front-end attack surface represents a category of operational risk with no traditional finance equivalent.
Technical solutions exist but remain unadopted. IPFS hosting, ENS domain resolution, local-first front-ends, and wallet-level transaction simulation can collectively eliminate or mitigate the attack vector. Adoption remains in single-digit percentages across the industry.
DeFi has spent billions making its back-end secure. Smart contract audits are now standard practice. Formal verification is increasingly common. Bug bounty programs offer six- and seven-figure rewards. The blockchain layer — the foundation of decentralized finance — has never been more robust.
And yet the front door remains unlocked.
The February 2026 attack wave is not a wake-up call. The industry has had those — Squarespace in 2024, Aerodrome in November 2025, and dozens of incidents in between. This is a structural failure. The DeFi industry continues to protect its vaults with bank-grade security while serving its websites through infrastructure that would embarrass a mid-2000s e-commerce startup.
The economic value at stake demands better. With over $100 billion in institutional capital flowing toward onchain protocols, the front-end attack vector is no longer a nuisance — it is a systemic risk to the credibility of decentralized finance. The technical solutions exist. IPFS, ENS, local-first architectures, and wallet-level verification can collectively close this gap. What remains missing is the will to implement them.
Until DeFi protocols treat their front-ends with the same seriousness they treat their smart contracts, the AngelFerno operators of the world will continue to walk through the front door.