DNS Hijack Hits OpenEden, Putting User Funds in Immediate Danger - Crypto Economy

TL;DR

  • OpenEden warned that its DNS was compromised and users may be redirected to a fake portal that steals assets when a wallet is connected.
  • Reserves remain intact and verifiable through the Chainlink Proof of Reserve. Smart contracts were not modified.
  • Similar attacks affected Aerodrome Finance and Curve Finance last year. The company did not provide a date to safely restore its services.

OpenEden reported that the DNS system for the domains openeden.com and portal.openeden.com was compromised. The company warned that accessing them through web browsers may lead users to a fake site and result in asset loss if a wallet is connected. The team issued an alert and asked users not to interact with those addresses while the incident is under investigation.

The platform stated that its reserve assets remain secure and can be verified through the Chainlink Proof of Reserve system. The incident did not affect the smart contracts or the actual custody. The risk appears if a user enters the compromised portal and signs transactions within the manipulated interface.

![](data:image/svg+xml,%3Csvg%20xmlns=‘http://www.w3.org/2000/svg’%20viewBox=‘0%200%20599%20491’%3E%3C/svg%3E)

OpenEden has operated since 2022 in Singapore as an institutional manager of tokenized real-world assets. The company issues the TBILL token, which provides exposure to U.S. Treasury bills backed by securities held in segregated accounts. The platform serves professional investors, DAO treasuries, and companies. The fund received A ratings from Moody’s and AA+ from S&P Global Ratings.

OpenEden Did Not Say When Services Will Be Restored

The attack relies on manipulation of the domain name system. Attackers alter records and redirect traffic to servers under their control. A user types the legitimate address, reaches an identical copy of the site, and connects a wallet. The page requests transaction signatures that appear normal but authorize token transfers to attacker addresses.

![](data:image/svg+xml,%3Csvg%20xmlns=‘http://www.w3.org/2000/svg’%20viewBox=‘0%200%201024%20400’%3E%3C/svg%3E)

In November 2025, Aerodrome Finance had its domain taken over and a fraudulent site enabled the theft of ETH, USDC, and other assets from many users. In May 2025, Curve Finance experienced an intrusion at its domain registrar and migrated to an alternative address while recommending access through ENS.

OpenEden did not detail the method used to gain control of the DNS or identify the attacker or attackers involved. The company also did not provide a date to restore secure access to the domains

LINK1.88%
AERO3.86%
CRV1.84%
ETH1.73%
此页面可能包含第三方内容,仅供参考(非陈述/保证),不应被视为 Gate 认可其观点表述,也不得被视为财务或专业建议。详见声明
  • 赞赏
  • 评论
  • 转发
  • 分享
评论
0/400
暂无评论
交易,随时随地
qrCode
扫码下载 Gate App
社群列表
简体中文
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)