BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Hackers Hijack Dead DeFi Domains to Steal Crypto, Coinspect Warns

Hackers Hijack Expired DeFi Domains to Steal Crypto from Unwary Users, Warns Coinspect

  • Hackers are seizing expired domains of defunct DeFi projects to steal users’ cryptocurrencies.
  • At least 100 cases of repurposed DeFi websites with malicious wallet-draining code have been documented.
  • Links to these domains still appear on reputable crypto platforms, increasing victim exposure.
  • Coinspect and other firms recommend that project owners renew or flag expired domains to prevent exploits.
  • The frequency and sophistication of these attacks may increase as more DeFi projects become inactive.

Hackers are gaining control of expired web domains from inactive decentralised finance (DeFi) projects and using them to deploy schemes that drain cryptocurrency from users’ wallets, according to findings published by security firm Coinspect on Wednesday. The targeted domains belong to projects that have shut down, making it easier for attackers to take over the sites and lure unsuspecting users.

- Advertisement -

So far, Coinspect has identified more than 100 cases where attackers have reactivated former DeFi project domains and inserted harmful code. Links to these compromised sites remained live on trusted crypto data platforms like DefiLlama and DappRadar until they were identified and removed. According to Chainalysis, 2024 is on pace to become the worst year for crypto theft, with digital criminals expected to exceed previous records set by incidents such as the $1.4 billion Bybit exchange hack earlier in the year.

Attackers replicate the original branding and credibility of these “zombie” DeFi sites to trick users into connecting their wallets or signing malicious transactions. As Coinspect noted, “By reusing the project’s original branding and reputation, attackers can trick users into signing malicious transactions.” Unlike traditional phishing scams, attackers do not need to send unsolicited messages; users may visit these sites directly through longstanding, reputable links.

One example cited was Astar Exchange, previously holding $3.5 million in investor funds before shutting down. Its expired domain was re-registered and transformed into a fake site that prompted users to withdraw funds, which actually authorized wallet-draining transactions. Other affected projects included ADAO, Andromeada, and Ladex Exchange.

Coinspect worked with DefiLlama and other data aggregators to delist compromised domains and identify at-risk projects. So far, 475 expired domains have been reported. The firm recommends defunct projects renew their domains, clearly post shutdown notices, and alert crypto data platforms and security teams about their status.

- Advertisement -

So far, the attacks have been basic and easy to detect, but Coinspect warns that future tactics could become more advanced and harder to spot. For more details, the company’s full analysis is available in their blog post.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Ex-Ethereum Devs Launch Ethlabs to Woo Institutions

Former Ethereum Foundation contributors and firms Bitmine and Sharplink have funded a new nonprofit,...

Bitcoin Optimism Rises, but $70K Breakout Stalls

Bitcoin's funding rate climbed to 7%, signaling growing bullish confidence, but persistent spot ETF...

ShapedPlugin WordPress Backdoor in Supply Chain

Pro versions of three ShapedPlugin WordPress extensions were backdoored after attackers hijacked the official...

Saylor’s Strategy Says Its Stock Differs From Terra’s

Analyst Mark Palmer from Benchmark-StoneX rejects comparisons between Strategy’s volatile STRC and the collapsed...

Coinbase Launches AI Pre-IPO Futures for OpenAI & Anthropic

Coinbase has launched pre-IPO perpetual futures for AI giants OpenAI and Anthropic, expanding its...

Must Read

7 Best Cryptocurrency Lending Platforms in 2025 (Ranked & Reviewed)

QUICK LINKSOur MethodologyHow to Choose the Best Crypto Lending Platform: Key Factors to ConsiderIn-Depth Reviews of the 7 Best Crypto Lending Platforms1. Nexo -...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading