Skip to content
Eth.limo Recovers Domain After easyDNS Hijack as Vercel Confirms Data Breach
5

Eth.limo Recovers Domain After easyDNS Hijack as Vercel Confirms Data Breach

ENS gateway eth.limo regained control of its domain after a social engineering attack on registrar easyDNS, while cloud platform Vercel disclosed a security breach through a compromised AI tool.

📝
CoinJP Editorial
0
CoinJP Editorial · 0 articles

Eth.limo Domain Hijacked Through Social Engineering

Ethereum Name Service (ENS) gateway eth.limo has published a detailed incident report following a domain hijacking attack. The breach targeted the project's domain registrar easyDNS rather than eth.limo's own infrastructure.

«https://t.co/of1ktfaPss» — ETH.LIMO 🦇🔊 (@eth_limo), original post

The attacker impersonated an eth.limo team member and initiated an account recovery procedure with easyDNS. Upon gaining access to the control panel, the hacker modified the nameserver (NS) records and redirected them to Cloudflare. This meant users accessing eth.limo could have been directed to phishing pages.

Why This Matters

Eth.limo serves as a bridge between Web2 and Web3, providing access to 2 million decentralized websites in the .eth domain zone. Compromising such a gateway could potentially put a massive number of decentralized web users at risk.

Ethereum co-founder Vitalik Buterin personally warned his audience about the issue, urging them to avoid visiting his blog and other .eth pages until the situation was resolved.

«The kind people at @eth_limo have warned me that there has been an attack on their DNS registrar. So please do not visit vitalik.eth.limo or other .eth.limo pages until they confirm that things are back to normal. You can check my blog via IPFS directly…» — vitalik.eth (@VitalikButerin), original post

DNSSEC Prevented Widespread Damage

easyDNS CEO Mark Jeftovic acknowledged the company's responsibility for the incident. He described the attack as "highly sophisticated" and stated that nothing like it had occurred in the registrar's 28-year history.

Major consequences were averted thanks to DNSSEC (Domain Name System Security Extensions). The attacker lacked the cryptographic signing keys required to validate DNS responses, so most DNS servers rejected the spoofed records. Instead of landing on malicious pages, users encountered error messages.

The eth.limo team confirmed that no user harm was detected. The project is migrating to Domainsure, a platform that does not support account recovery through customer support — effectively eliminating the social engineering vector used in this attack.

Vercel Confirms Client Data Breach

In a separate but concurrent security event, cloud provider Vercel disclosed that hackers gained access to a portion of its customers' credentials.

«We've identified a security incident that involved unauthorized access to certain internal Vercel systems, impacting a limited subset of customers.» — Vercel (@vercel), original post

Vercel CEO Guillermo Rauch revealed that the attack originated from the compromise of Context.ai, an AI tool used by a Vercel employee. Through this entry point, attackers penetrated the company's Google Workspace account and subsequently its internal systems.

«A Vercel employee got compromised via the breach of an AI platform customer called Context.ai that he was using…» — Guillermo Rauch (@rauchg), original post

Before Vercel's official statement, a listing appeared on the hacking forum BreachForums offering the stolen data for $2 million. The seller claimed to have source code and access keys.

«VERCEL just got breached. They're selling internal DB + employee accounts + GitHub/NPM tokens for $2M on BreachForums.» — shirish (@shiri_shh), original post

Vercel's leadership urged customers to immediately rotate credentials and monitor activity within their environments. Rauch emphasized that the infrastructure of open-source projects, including the Next.js framework, was not affected.

A Wave of Crypto Security Incidents

Both events unfolded against a backdrop of major attacks across the crypto industry. On April 1, DeFi platform Drift Protocol on Solana lost at least $280 million in a hack. On April 17, liquid restaking protocol Kelp was drained of $293 million following a cross-chain bridge exploit. The combined damage from these incidents underscores the scale of security challenges facing the Web3 space.

cybersecuritydata-breachdns-hijackensethereumvercelweb3-security

Frequently Asked Questions

What happened to eth.limo and how was the domain hijacked?

An attacker impersonated an eth.limo team member and used easyDNS's account recovery process to gain control of the domain. The hacker then changed the nameserver records to redirect traffic through Cloudflare, potentially exposing users to phishing.

What is eth.limo and why is it important?

Eth.limo is a gateway bridging Web2 and Web3, providing access to 2 million decentralized websites in the .eth domain zone. It allows standard web browsers to access content hosted on decentralized networks via ENS.

How did DNSSEC prevent damage during the eth.limo attack?

DNSSEC requires cryptographic signatures for DNS records, which the attacker did not possess. Most DNS servers rejected the spoofed responses, so users saw error messages instead of malicious pages.

How was Vercel breached and what data was compromised?

The attack started with the compromise of Context.ai, an AI tool used by a Vercel employee. Through this vector, hackers accessed the company's Google Workspace and internal systems. The stolen data was listed for sale at $2 million on BreachForums.

What platform is eth.limo migrating to after the incident?

Eth.limo is moving to Domainsure, a platform that does not support account recovery through customer support. This eliminates the social engineering attack vector that was exploited in this incident.

Read also

AI

AI Audit Uncovers Critical Liveness Bug in Ethereum's Nethermind Client

Octane Security's AI discovered a high-severity vulnerability in the Nethermind execution client that could have halted block production for 38% of Ethereum mainnet validators. The Ethereum Foundation awarded a maximum $50,000 bounty.

3 min·🔥 1
Market

Bitcoin Down 2.5% Weekly: Jane Street Accusations & 7 Ethereum Forks

Bitcoin lost ~2.5% over the week amid macro shocks and geopolitical tensions. Jane Street faced market manipulation allegations while Ethereum unveiled an ambitious seven hard fork roadmap through 2029.

6 min·🔥 1
Business

TON Wallet Introduces Yield Vaults for BTC, ETH, and USDT Directly in Telegram

TON Wallet has launched yield vaults for BTC, ETH, and USDT directly within Telegram, offering up to 18% APY on stablecoins through partnerships with Morpho, TAC, and Re7.

2 min·🔥 1
Market

Bitcoin Hits $70,000 as Iran Ceasefire Talks Boost Risk Appetite

Bitcoin surged 4% to test the $70,000 level on April 6 amid reports of ceasefire negotiations between the US, Israel, and Iran. The derivatives market, however, sends mixed signals.

3 min·🔥 0
Analytics

Bitcoin Rebounds to $70,000 as Leverage Drops and ETF Inflows Continue

BTC recovered above $70,000 on March 10, erasing weekend losses. Spot ETFs attracted $568M in weekly inflows while the estimated leverage ratio on Binance fell sharply from 0.198 to 0.152.

3 min·🔥 0
Market

Bitcoin Drops Below $67,000 as Ethereum Foundation Unveils Quantum Defense Roadmap

Bitcoin lost 3% over the week amid Middle East tensions and ETF outflows, miner activity hit historic lows, and Ethereum Foundation outlined a four-hardfork plan for quantum resistance by 2029.

4 min·🔥 0