Fri, Jul 01, 2022
Aliens TLDR
The hacker accessed Polygon and Fantom’s remote procedure call (RPC) interfaces through the Web3 infrastructure platform Ankr by tricking a third party domain name system (DNS) provider into giving the hacker access to Polygon and Fantom’s domains.
Ankr’s DNS is hosted on a web service named Gandi, and its customer support has a section for clients who want to change the administrator’s email for a domain.
Posing as an Ankr employee, the hacker sent Gandi a fake identity card and convinced the platform’s customer support service to change the email address for the domain registrar account from Ankr’s to the hacker’s Hotmail account.
Sources at Polygon and Ankr told Blockworks that no user funds were compromised, but also conceded they cannot conclusively determine whether any users fell victim to the phishing attack.
Everything happening in the crypto world, in real time
Recommended Stories