Curve Finance did not solve the problem of hacking the site after 4 hours

Johny Smith

2025/06/06

2 mins read


The Curve Finance team said that the official website of the project was attacked. Attackers intercepted the DNS management and set up forwarding to the harmful page. An attempt to interact with a fake site can lead to a complete loss of funds in a cryptocurrent. The team immediately warned users not to use the web interface until the problem is eliminated. The incident was confirmed by representatives of Certik, SlowMist and Scam Sniffer, pointing out the high risk of phishing.

Curve Finance noted that all smart contracts remain in working condition and did not suffer from the attack. The problem only affected the Frontend-the user interface that connects to the blockchain services. Despite this, the project urgently asks not to use the official site until the threat is completely eliminated. An alternative can be access to the protocol through IPFS or direct interaction through wallets.

At the time of publication, more than 4 hours have passed since the 1st warning. However, the Curve team has not yet restored access to the domain. Users in social networks express dissatisfaction with a protracted pause in the reaction and believe that such a large Defi project should have clear instructions for emergency recovery. The leadership of the platform does not yet call the reasons for the delay and does not publish the deadlines for eliminating the consequences.

Users indicate the weak preparedness of the team for such incidents and the lack of an operational anti -crisis protocol. For comparison, cases of other large projects are given that eliminated similar attacks in 1-2 hours. Some participants of the Defi community are already calling for temporarily abandoning Curve even through alternative interfaces, until there are complete security guarantees.