ChainBleedv0.1 · open intel
← back to feed·INFRASTRUCTURE2023-09-20 · 2y ago
Incident · SLOWMIST

Balancer

DNS Hijacking Attack
Estimated loss
$350.0K
VERDICT —OUT OF SCOPE
Root cause is infrastructure (DNS / cloud / database / third-party API) compromise, not on-chain contract logic. Pre-deployment source review would not surface this; coverage lives in cloud-security + supply-chain audit, separate discipline.
▰ METHOD
INFRASTRUCTURE
INFRASTRUCTURE
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

▰ PROOF OF CONCEPT
DEFIHACKLABS
src/test/2023-08/Balancer_exp.sol
view forked test on github ↗

Reproducible Foundry test fork from SunWeb3Sec/DeFiHackLabs. Clone the repo, run forge test against the file path above, and replay the exploit against a mainnet fork at the historical block. Use for reproduction only — not for live targets.

Forensic narrative

On September 20th, the DeFi liquidity protocol Balancer fell victim to a DNS hijacking attack. Funds have been directed to an address starting with 0x6457, resulting in a total loss of approximately $350,000. The attacker’s fee came from the phishing group AngelDrainer. The attacker may be related to Russia. Attack method (per SlowMist): DNS Hijacking Attack. Reported loss: $ 350,000.

Primary source
https://twitter.com/Balancer/status/1704402769535438928
Sourced from
slowmist
Technical record
chain
protocol
Balancer
bug_class
infrastructure
date_occurred
2023-09-20
loss_usd
$350,000
source_id
sm:balancer::2023-09-20
Related — same bug class· infrastructure
2026-04-18
1mo ago
Kelp DAO
Infrastructure-level attack
infrastructure
$293.00M
OUT OF SCOPE
2026-04-18
1mo ago
DNS registrar for eth.limo
DNS hijacking
infrastructure
OUT OF SCOPE
2026-04-04
2mo ago
HypurrFi
Domain Hijacking
infrastructure
OUT OF SCOPE
2026-03-31
2mo ago
Steakhouse Financial
Social Engineering
infrastructure
OUT OF SCOPE
2026-03-19
2mo ago
Neutrl
DNS Hijacking
infrastructure
OUT OF SCOPE
2026-03-18
2mo ago
ETH
Neutrl
DNS Hijacking Attack
infrastructure
OUT OF SCOPE
ChainBleed — live web3 threat intelligence