Scan to download
BTC $65,573.03 +3.51%
ETH $1,911.62 +4.46%
BNB $595.85 +0.69%
XRP $1.42 -4.56%
SOL $81.67 -4.53%
TRX $0.2795 -0.47%
DOGE $0.0974 -3.83%
ADA $0.2735 -4.22%
BCH $500.76 +2.99%
LINK $8.64 -2.97%
HYPE $28.98 -1.81%
AAVE $122.61 -3.42%
SUI $0.9138 -6.63%
XLM $0.1605 -4.62%
ZEC $260.31 -8.86%
BTC $65,573.03 +3.51%
ETH $1,911.62 +4.46%
BNB $595.85 +0.69%
XRP $1.42 -4.56%
SOL $81.67 -4.53%
TRX $0.2795 -0.47%
DOGE $0.0974 -3.83%
ADA $0.2735 -4.22%
BCH $500.76 +2.99%
LINK $8.64 -2.97%
HYPE $28.98 -1.81%
AAVE $122.61 -3.42%
SUI $0.9138 -6.63%
XLM $0.1605 -4.62%
ZEC $260.31 -8.86%

Kelp DAO Security Incident Analysis: The attacker impersonated the Kelp team to persuade GoDaddy's customer support to bypass 2-FA verification

2024-07-29 16:33:25
Collection

ChainCatcher message, the liquidity staking protocol Kelp DAO reviews the previous security incident: On July 22 at 22:30, Kelp's dApp began displaying transactions from malicious wallet activities attempting to steal user funds. The Kelp team responded immediately, locking down the domain name server, restoring ownership access, and resolving the issue.

The attacker impersonated the Kelp team and successfully convinced GoDaddy's customer support to bypass 2-FA. The Kelp team is taking preventive measures, including migrating to another domain registrar and strengthening alerts for abnormal UI behavior. A few users reported losing funds due to UI attacks, and the Kelp team is providing support.

Related tags
app_icon
ChainCatcher Building the Web3 world with innovations.