Six decentralized finance protocols have suffered domain name system (DNS) hijacking attacks since February 2026, draining an estimated $2.7 million from users despite zero smart contract compromises. The attack vector — social engineering domain registrars to redirect front-end traffic to phishi...
"DeFi hacking has become an infinitely sustainable and viable business." — Mitchell Amador, Founder & CEO, Immunefi
Six decentralized finance protocols have suffered domain name system (DNS) hijacking attacks since February 2026, draining an estimated $2.7 million from users despite zero smart contract compromises. The attack vector — social engineering domain registrars to redirect front-end traffic to phishing clones — has emerged as the most consistent threat to the $95.4 billion DeFi ecosystem this year. CoW Swap became the latest victim on April 14, losing $1.2 million in user funds within three hours.
The pattern is uniform: attackers bypass on-chain security entirely, targeting the off-chain web infrastructure that connects users to otherwise secure protocols. Smart contracts remain intact. Backend systems go untouched. Yet users lose funds because the interface they trust is a forgery. According to data from TechnologyChecker.io, only 0.47% of DNS queries globally are protected by end-to-end DNSSEC validation as of Q1 2026 — a statistic that contextualizes the industry's exposure.
The economic implication is direct: protocols have invested billions in smart contract audits and on-chain security while leaving front-end infrastructure — the primary point of user interaction — protected by the same Web2 registrar systems vulnerable to phone calls, forged documents, and social engineering. The gap between on-chain security spending and off-chain infrastructure protection represents a structural mispricing of risk.
Six confirmed DNS hijacking incidents have hit DeFi protocols between February and April 2026:
| Date | Protocol | Domain | Estimated Loss | TVL at Risk | |------|----------|--------|---------------|-------------| | Feb 16 | OpenEden | openeden.com | Not disclosed | N/A | | Mar 11 | Bonk.fun | bonk.fun | ~$30,000 | N/A | | Mar 19 | Neutrl | neutrl.fi | Not disclosed | N/A | | Apr 3 | HypurrFi | hypurr.fi | $0 (intercepted) | ~$30M | | Apr 14 | CoW Swap | cow.fi | ~$1.2M | N/A | | Ongoing | Multiple .fi domains | Various | Varies | N/A |
For context, this pace exceeds 2025, when Curve Finance's curve.fi domain was hijacked in May 2025 via registrar-level manipulation of iwantmyname, resulting in traffic redirection to a static phishing page. That incident prompted Curve to migrate permanently to curve.finance.
The Q1 2026 broader crypto security picture is dominated by larger-scale attacks. According to Immunefi, the industry lost $1.64 billion in Q1 2026 across 40 incidents, with 94% of losses attributable to centralized finance exploits — principally the $1.46 billion Bybit hack in February. DeFi-specific losses totaled $106.8 million across 38 incidents. The DNS hijack vector, while smaller in aggregate dollar terms, is notable for its consistency and replicability.
Every 2026 DNS hijack has followed the same playbook:
Step 1: Registrar Compromise. Attackers contact the domain registrar — not the protocol team — and use social engineering to gain account access. Methods include forged identity documents, manipulated email change requests, and direct contact with registrar support staff. In CoW Swap's case, according to the post-mortem, attackers "manipulated the .fi domain registration process via social engineering" and used "forged identity documents to take over the domain." HypurrFi traced its breach to social engineering at Openprovider registrar.
Step 2: DNS Record Modification. Once registrar access is obtained, attackers modify DNS records to point the protocol's domain to attacker-controlled servers hosting a phishing clone.
Step 3: Phishing Interface Deployment. The cloned front-end presents a transaction interface identical to the legitimate protocol. Users connecting wallets are prompted to sign malicious transactions — typically token approval transactions that grant the attacker permission to drain wallets.
Step 4: Extraction Window. The attack window is typically 90 minutes to several hours before detection. CoW Swap's hijack lasted approximately 90 minutes before the team issued a public warning at 15:41 UTC. The short window limits total losses but creates concentrated damage to users active during that period.
At no point do attackers interact with smart contracts, backend APIs, or protocol infrastructure. The entire attack surface is the registrar's customer support and identity verification process — a Web2 vulnerability exploiting Web3 user trust.
A notable pattern has emerged around Finland's .fi country-code top-level domain (ccTLD), which multiple DeFi protocols adopted for branding purposes. According to Web3SecNews, four DeFi protocols using .fi domains were hit "inside a few weeks" in early 2026.
The cluster includes:
The .fi TLD is administered by the Finnish Transport and Communications Agency (Traficom), and registration is available through accredited registrars. The concentration of attacks on this TLD suggests either a systemic vulnerability in the .fi registration workflow, a common registrar used across multiple protocols, or targeted exploitation of a known weakness in the .fi domain transfer process. Post-mortem reports from affected protocols indicate that social engineering at the registrar level — rather than any technical flaw in the .fi infrastructure itself — was the consistent root cause.
Following its May 2025 hijack, Curve Finance migrated to curve.finance and publicly urged the industry to consider ENS (Ethereum Name Service) for decentralized, censorship-resistant domain resolution. Neutrl completed a DNS migration to a new provider and announced plans to phase out its original .fi domain.
Direct financial losses from the six 2026 DNS hijacks total approximately $2.7 million in confirmed and estimated figures, though several incidents lack disclosed totals. The breakdown:
Indirect costs are harder to quantify but economically significant. Protocol teams incur domain migration expenses, security audit costs, and engineering time for incident response. Reputational damage affects user retention and TVL. Curve Finance processed over $400 million in on-chain volume during its front-end outage, demonstrating that sophisticated users can bypass compromised interfaces — but retail users cannot.
The total $1.64 billion in Q1 2026 crypto losses reported by Immunefi dwarfs the DNS hijacking total. But the per-incident economics differ: DNS hijacks require minimal technical sophistication, no zero-day exploits, and no on-chain interaction. The barrier to entry is a convincing phone call or forged document. The attack is repeatable across any protocol using traditional domain registration.
Domain Name System Security Extensions (DNSSEC) provide cryptographic authentication of DNS records, theoretically preventing unauthorized modifications. According to TechnologyChecker.io's Q1 2026 report, end-to-end DNSSEC validation covers just 0.47% of DNS queries globally. While 8.11% of queries reach DNSSEC-signed domains, the gap between signing and validation means the protection is largely theoretical.
Among .com domains — the most widely used TLD — DNSSEC adoption stands at 5%, according to 2024 data from Internet Society. No public data exists on DNSSEC adoption specifically among DeFi protocol domains, but the prevalence of successful DNS hijacks suggests it remains minimal.
End-to-end DNSSEC validation grew 45% year-over-year, according to TechnologyChecker.io. The growth rate is encouraging but insufficient: at current trajectory, meaningful adoption remains years away.
DNSSEC alone does not prevent registrar-level compromise. An attacker who gains full registrar access can modify DNSSEC records alongside DNS records. The defense requires layered security: registrar account hardening, multi-factor authentication with hardware keys, domain locking, transfer authorization codes, and monitoring for unauthorized record changes.
The industry has responded with both traditional and crypto-native mitigation strategies.
Traditional Measures. Security recommendations from DomainSure and other providers include: using enterprise-grade registrars (Cloudflare, MarkMonitor, AWS Route53) rather than commodity providers; enabling registrar lock and transfer lock; requiring hardware security keys for account access; implementing DNSSEC; and establishing monitoring for DNS record changes.
On-Chain Domain Solutions. 3DNS, an on-chain domain registrar compatible with both Web2 and Web3, offers domains as NFTs stored in user wallets on the Optimism L2. Per 3DNS documentation, "a hacker needs access to your private key to steal your domain," eliminating the registrar social engineering vector. However, on-chain domain resolution introduces its own complexities: dependency on blockchain availability, user experience friction, and limited TLD support.
ENS Integration. Ethereum Name Service provides decentralized domain resolution secured by Ethereum consensus. Curve Finance endorsed ENS as a safer alternative following its 2025 hijack. ENS adoption among DeFi protocols remains limited, partly because ENS .eth domains require specialized browser support or gateways, creating friction for mainstream users.
Wallet-Level Protection. Several wallet providers — including MetaMask and Rabby — have implemented phishing detection that flags known malicious domains. In HypurrFi's case, major wallets blocked the hijacked domain before significant losses occurred, suggesting that downstream protection can partially compensate for upstream domain vulnerabilities.
The fundamental tension remains: DeFi protocols promote decentralization and trustlessness at the smart contract layer while relying on centralized, trust-dependent infrastructure at the front-end layer. The economic incentive to resolve this gap increases with each successful hijack.
The 2026 DNS hijacking wave reveals a consistent failure mode: DeFi protocols have treated domain infrastructure as a commodity input rather than a critical security surface. The attack vector requires no on-chain interaction, no smart contract exploitation, and no technical novelty. A forged document and a registrar support ticket are sufficient.
The economic logic is clear. Protocols managing tens of billions in TVL rely on domain registrar support staff — earning modest wages and processing hundreds of tickets daily — as the de facto gatekeepers of user fund security. The mismatch between the value at stake and the security of the access point is the vulnerability.
Solutions exist across the stack: enterprise registrars, DNSSEC, on-chain domain resolution, and wallet-level phishing detection. Adoption has been slow, driven partly by cost and partly by the assumption that on-chain security is sufficient. Six incidents in ten weeks suggest that assumption carries a measurable price.