← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] DeFi's $97B Frontend Is Its Weakest Link

Zephyra|March 20, 2026|BPF
EXECUTIVE SUMMARY

On March 19, 2026, DeFi protocol Neutrl paused smart contracts after a suspected DNS hijack redirected its frontend to a malicious interface. No smart contract vulnerability was exploited. No private key was compromised. An attacker socially engineered the protocol's DNS provider, swapped the dom...

"The association to Inferno Drainer is clear as shared onchain and offchain infrastructure. Roughly 228 DeFi protocol front ends are still at risk." — Ido Ben-Natan, CEO, Blockaid

Executive Summary

On March 19, 2026, DeFi protocol Neutrl paused smart contracts after a suspected DNS hijack redirected its frontend to a malicious interface. No smart contract vulnerability was exploited. No private key was compromised. An attacker socially engineered the protocol's DNS provider, swapped the domain's destination, and waited for users to connect wallets. It is the third major DNS frontend attack on a DeFi protocol in 2026 alone, following OpenEden on February 16 and Aerodrome/Velodrome in late 2025.

The pattern is now unmistakable. According to Halborn's Top 100 DeFi Hacks Report, off-chain attacks accounted for 80.5% of stolen funds in 2024, with compromised accounts making up 55.6% of all incidents. Smart contract exploits — the attack vector the industry has spent billions auditing against — represent a declining share of total losses. Meanwhile, DeFi's total value locked stands at approximately $97.6 billion as of March 2026, according to DefiLlama, and nearly all of it is accessed through centralized web frontends that rely on the same DNS infrastructure as any restaurant website.

This report examines the structural vulnerability, maps the incident history, quantifies the exposure, and evaluates the emerging mitigations — from ENS/IPFS decentralized hosting to Liquity's operator-incentive model.

Table of Contents

  1. The Attack Anatomy: How DNS Hijacks Work Against DeFi
  2. Incident Timeline: 2022–2026
  3. The Numbers: Off-Chain Attacks Now Dominate
  4. The Permit2 Amplifier
  5. Why DNSSEC Adoption Remains Low
  6. The Bybit Precedent: Frontend as Kill Chain
  7. Mitigation Approaches
  8. Key Takeaways
  9. Conclusion
  10. Sources & References

The Attack Anatomy: How DNS Hijacks Work Against DeFi

A DeFi DNS hijack requires no blockchain expertise. The attack targets the domain name system — the internet's phone book — rather than the protocol's smart contracts. The sequence is straightforward:

  1. Compromise the registrar or DNS provider. This is typically achieved through social engineering, credential theft, or exploiting weak access controls (e.g., missing two-factor authentication). In the Squarespace incident of July 2024, a forced domain migration from Google Domains removed 2FA protections entirely, exposing over 220 DeFi protocol frontends simultaneously.

  2. Modify DNS A or CNAME records. The attacker redirects the domain to an IP address hosting a pixel-perfect replica of the legitimate frontend. In the Aerodrome attack of November 2025, DNSSEC was stripped from both .box and .finance domains before records were altered. A compromised insider at registrar NameSilo facilitated the redirect.

  3. Serve a wallet-draining interface. The phishing frontend presents normal-looking transaction prompts. In the Aerodrome case, the fake UI first requested a simple message signature containing only the value "1," then immediately fired multiple approval prompts targeting NFTs, ETH, USDC, WETH, and other assets — all requesting unlimited spend permissions.

  4. Drain connected wallets. Once a user signs approval transactions on the spoofed interface, the attacker's contracts execute transferFrom() calls to empty the wallet.

The entire chain — from DNS provider compromise to first drained wallet — can complete in under an hour. The smart contracts remain untouched. The blockchain is functioning as designed. The vulnerability sits entirely in Web2 infrastructure.

Incident Timeline: 2022–2026

| Date | Protocol | Attack Vector | Confirmed Losses | |------|----------|---------------|-----------------| | Aug 2022 | Curve Finance | DNS hijack via registrar | $575,000 | | Sep 2023 | Galxe | DNS hijack | 1,100 wallets drained | | Jul 2024 | Compound, Celer, 220+ protocols | Squarespace DNS migration exploit | Undisclosed | | Sep 2024 | Puffer Finance | DNS hijack | Undisclosed | | Oct 2025 | Garden Finance, Typus Finance, Abracadabra | DNS-related breach + oracle manipulation | $16.2 million | | Nov 2025 | Aerodrome, Velodrome | NameSilo insider + DNS hijack | $700,000 | | Feb 2026 | OpenEden | DNS hijack (both main site + portal) | Under investigation | | Mar 2026 | Neutrl | DNS provider social engineering | Under investigation |

The frequency is accelerating. In 2022 and 2023, DNS attacks on DeFi protocols were isolated incidents. Since mid-2024, they have become a recurring pattern, with at least eight distinct events in 18 months. The Squarespace incident exposed a systemic supply-chain risk: a single registrar migration decision endangered more than 220 protocol frontends simultaneously.

The Numbers: Off-Chain Attacks Now Dominate

The industry narrative around DeFi security has historically centered on smart contract exploits — reentrancy bugs, oracle manipulation, flash loan attacks. The data now contradicts that focus.

According to Halborn's analysis of the top 100 DeFi hacks:

  • Off-chain incidents accounted for 56.5% of attacks and 80.5% of stolen funds in 2024
  • Compromised accounts represented 55.6% of all incidents in the same period
  • Over 54% of off-chain attacks lack clear forensic origins, meaning the attack surface is not well understood even after the fact

Chainalysis reported that total cryptocurrency theft reached $3.41 billion in 2025. The single largest incident — Bybit's $1.4 billion loss in February 2025 — was a frontend supply-chain attack, not a smart contract exploit. North Korean threat actors alone accounted for $2.02 billion, or 59% of the annual total, with the majority targeting off-chain infrastructure.

The gap between where the industry spends security budgets (smart contract audits) and where the losses actually occur (off-chain infrastructure) is widening.

The Permit2 Amplifier

Uniswap's Permit2 contract, designed to improve token approval UX by enabling gasless, off-chain signatures, has inadvertently amplified the damage from frontend attacks.

When a user interacts with a compromised frontend, the phishing interface can request a Permit2 signature — an off-chain approval that grants the attacker's contract permission to move tokens without requiring an additional on-chain approval transaction. The user sees what appears to be a routine signature request. The approval is silent, gasless, and often unlimited in scope.

In the Neutrl incident, the protocol's team specifically urged users to revoke all Permit2 approvals via revoke.cash. This recommendation has become standard incident response for DNS hijacks, indicating that Permit2 approvals are a primary extraction mechanism for frontend phishing attacks.

The Permit2 vulnerability has contributed to cumulative losses of $26.8 million according to one tracking estimate. The mechanism is structurally difficult to defend against because the signature request is indistinguishable from a legitimate Permit2 interaction — the difference lies entirely in which contract receives the approval.

Why DNSSEC Adoption Remains Low

DNSSEC (Domain Name System Security Extensions) provides cryptographic authentication of DNS data, making hijacked records detectable. It is the most direct technical mitigation against the attack vector described above.

Adoption rates remain low:

  • 5% of .com domains are signed with DNSSEC (2024 data)
  • 26% of organizations globally have implemented DNSSEC
  • EU average DNSSEC validation rate: 49.4%, versus a global rate of 35.4% (Q3 2025, European Commission data)

No comprehensive study of DNSSEC adoption among DeFi protocols has been published. However, the fact that DNS hijacks continue to succeed — with DNSSEC explicitly stripped in the Aerodrome case — suggests adoption is low among crypto frontends. The Squarespace incident demonstrated that even when protocols had DNSSEC enabled, a registrar migration could silently remove it.

The barriers to DNSSEC adoption are operational, not technical: it adds complexity to DNS management, can cause resolution failures if misconfigured, and many registrars do not enable it by default.

The Bybit Precedent: Frontend as Kill Chain

The February 21, 2025, Bybit hack — at $1.4 billion, the largest cryptocurrency theft in history — was not a smart contract exploit. It was a frontend attack.

North Korean threat actors (tracked as TraderTraitor/Jade Sleet) compromised a macOS workstation belonging to a Safe{Wallet} developer on February 4, 2025. Using stolen AWS credentials, they accessed the S3 bucket hosting the JavaScript for Safe{Wallet}'s web interface at app.safe.global. On February 19, they injected malicious JavaScript that altered transaction requests specifically when Bybit's cold wallet was accessed.

When Bybit's authorized signers reviewed what appeared to be a routine internal transfer, they were approving a request that handed over control of the cold wallet smart contract to the attackers. 401,347 ETH was drained.

The attack confirmed what the DNS hijack pattern had already suggested: the frontend is the kill chain. Smart contracts can be formally verified, audited by multiple firms, and running flawlessly on an immutable ledger — and none of that matters if the interface that humans use to interact with those contracts is compromised.

Mitigation Approaches

ENS + IPFS Decentralized Hosting

The most architecturally pure solution replaces DNS entirely. ENS (Ethereum Name Service) stores a content hash on-chain, pointing to frontend code hosted on IPFS (InterPlanetary File System). IPFS content identifiers (CIDs) are cryptographically derived from the content itself — any modification to a single byte of frontend code produces an entirely different CID, making tampering detectable by design.

Protocols like ENS domains with eth.limo gateways allow users to access DeFi frontends via protocol.eth.limo URLs, bypassing DNS entirely. Tools like Omnipin deploy frontends to IPFS with content pinned to Filecoin, secured by a Safe multisig for updates.

The tradeoff: IPFS gateways introduce a centralization point. Loading times are slower. User experience remains inferior to traditional hosting. Browser support for .eth domains is limited.

Liquity's Decentralized Frontend Operator Model

Liquity AG operates no official frontend. Instead, it incentivizes third-party operators to run independent frontends through a kickback mechanism: operators earn a share of LQTY rewards generated by deposits facilitated through their interface, with configurable kickback rates between 0% and 100%.

This model distributes the attack surface across dozens of independent operators. A DNS hijack of one frontend does not compromise the protocol. Users can switch to an alternative frontend immediately. The model has been running since Liquity V1 launch without a successful frontend attack.

The tradeoff: UX fragmentation. Users must choose between multiple frontends with varying quality. Brand cohesion is difficult to maintain.

Wallet-Level Transaction Simulation

MetaMask, Coinbase Wallet, and other wallet providers have implemented transaction simulation and phishing detection. In the Aerodrome incident, major wallets began displaying warnings within two minutes of the first malicious transaction. Blockaid's real-time threat detection flagged the Squarespace hijack within minutes.

These defenses are reactive — they detect attacks after they begin but cannot prevent the DNS compromise itself. They also depend on wallet providers maintaining current threat databases.

Operational Hardening

The most immediate mitigations are operational:

  • Hardware security keys (not SMS 2FA) for registrar access
  • DNSSEC enforcement with monitoring for unauthorized removal
  • Registrar lock features (clientTransferProhibited, clientDeleteProhibited)
  • Multi-party approval for DNS record changes
  • Use of enterprise-grade registrars (Cloudflare, MarkMonitor, AWS Route 53) over consumer-grade services

Key Takeaways

  • DNS hijacks have become DeFi's most consistent recurring attack vector, with at least eight major incidents since mid-2024 and accelerating frequency in 2026.
  • Off-chain attacks now account for 80.5% of stolen DeFi funds, according to Halborn's data. The industry's security spending remains disproportionately focused on smart contract audits.
  • The Bybit hack ($1.4B) confirmed the frontend as the primary kill chain for the most damaging attacks. The smart contract worked correctly; the interface lied to its users.
  • DNSSEC adoption among DeFi frontends appears negligible. The Squarespace incident demonstrated that registrar migrations can silently remove existing protections.
  • Permit2 gasless approvals amplify the damage from frontend attacks by allowing silent, unlimited token approvals through off-chain signatures.
  • Decentralized hosting (ENS + IPFS) and distributed frontend models (Liquity) offer structural solutions but impose UX costs that most protocols have not accepted.
  • $97.6 billion in DeFi TVL is accessed primarily through centralized web frontends. The attack surface is structural, not incidental.

Conclusion

DeFi has spent four years and hundreds of millions of dollars hardening smart contract security. Formal verification, multi-firm audit cycles, bug bounty programs, and real-time monitoring have made on-chain code substantially more resilient. The smart contract exploit share of total losses is declining.

The frontend — a standard web application running on traditional DNS, hosted on AWS S3 or Vercel, managed through consumer-grade registrars — has become the path of least resistance. It requires no blockchain expertise to attack. Social engineering a GoDaddy support agent is cheaper than finding a reentrancy bug in a formally verified contract.

The industry's response has been largely reactive: revoke approvals, warn users, switch registrars, wait for the next incident. Structural solutions exist — decentralized hosting, distributed frontend models, hardware-secured registrar access — but adoption remains marginal. The incentive structure is misaligned: protocols invest in audits that earn marketing credibility, while DNS security is invisible until it fails.

With $97.6 billion in TVL accessed through conventional web infrastructure, and off-chain attacks accounting for four-fifths of stolen funds, DeFi's weakest link is not on the blockchain. It is the browser tab.

Sources & References

  1. Neutrl DeFi Pauses Smart Contracts Amid Suspected DNS Frontend Hijack — CryptoTimes, March 19, 2026
  2. OpenEden Reports DNS Hijack, Warning of Wallet Asset Theft Risk — BingX News, February 16, 2026
  3. Aerodrome Finance Hit by Front-End Attack — CoinDesk, November 2025
  4. Halborn: The Top 100 DeFi Hacks Report 2025 — Off-chain attack statistics and trends
  5. More Than 220 DeFi Protocols Still at Risk From Squarespace DNS Hijack — Decrypt, July 2024
  6. Bybit Hack Traced to Safe{Wallet} Supply Chain Attack — The Hacker News, February 2025
  7. 2025 Crypto Theft Reaches $3.4 Billion — Chainalysis, 2026
  8. Squarespace Domain Hijacking Incident: Attack Report — Blockaid Blog
  9. Aerodrome DNS Attack Resulted in User Losses of Approximately $700,000 — PANews
  10. DeFi TVL Surges to $97.6B While Markets Panic — SpotedCrypto, March 2026
  11. Liquity Runs on Decentralized Frontends — Liquity Blog
  12. Halborn: Bybit Hack — Smart Contract Audits Won't Stop Off-Chain Attacks — Halborn Blog
  13. Uniswap Permit2 Contract Exploit Has Cost $26.8M in Damages — Router Protocol / Medium
  14. DNSSEC Statistics — Internet Society
  15. A Practical Guide to Decentralized Websites — ENS Blog