ChainBleedv0.1 · open intel
← back to feed·INFRASTRUCTURE2022-05-14 · 4y ago
Incident · SLOWMIST

SpiritSwap

Malicious Code Injection Attack
Estimated loss
$18.0K
VERDICT —OUT OF SCOPE
Root cause is infrastructure (DNS / cloud / database / third-party API) compromise, not on-chain contract logic. Pre-deployment source review would not surface this; coverage lives in cloud-security + supply-chain audit, separate discipline.
▰ METHOD
INFRASTRUCTURE
INFRASTRUCTURE
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

Forensic narrative

SpiritSwap tweeted that the front-end server placed on AWS was compromised by hackers, the website was tampered with parameters, and $18,000 was currently stolen. According to official postmortem analysis, the attackers contacted GoDaddy and began a social engineering attack on one of its employees. After gaining access to the account, the attackers proceeded to modify DNS settings and change all credentials, effectively hijacking access and Take ownership for yourself. After securing access to the SpiritSwap domain, the attackers then proceeded to deploy a phishing site tricked into appearing to be SpiritSwap. The attacker then uses the "send to" function in the exchange contract to reroute any funds exchanged by the user to the attacker's address. Attack method (per SlowMist): Malicious Code Injection Attack. Reported loss: $ 18,000.

Primary source
https://twitter.com/Spirit_Swap/status/1525216379041116160
Sourced from
slowmist
Technical record
chain
protocol
SpiritSwap
bug_class
infrastructure
date_occurred
2022-05-14
loss_usd
$18,000
source_id
sm:spiritswap::2022-05-14
Related — same bug class· infrastructure
2026-04-18
1mo ago
Kelp DAO
Infrastructure-level attack
infrastructure
$293.00M
OUT OF SCOPE
2026-04-18
1mo ago
DNS registrar for eth.limo
DNS hijacking
infrastructure
OUT OF SCOPE
2026-04-04
2mo ago
HypurrFi
Domain Hijacking
infrastructure
OUT OF SCOPE
2026-03-31
2mo ago
Steakhouse Financial
Social Engineering
infrastructure
OUT OF SCOPE
2026-03-19
2mo ago
Neutrl
DNS Hijacking
infrastructure
OUT OF SCOPE
2026-03-18
2mo ago
ETH
Neutrl
DNS Hijacking Attack
infrastructure
OUT OF SCOPE
ChainBleed — live web3 threat intelligence