Unexpectedly, the ENS gateway known as eth.limo revealed a DNS hijack stemming from a social engineering scheme aimed at EasyDNS, its domain provider. Though settings shifted temporarily under unauthorized access, safeguards held firm throughout. Protection layers blocked harm, keeping user activity untouched during the episode. Compromise occurred at the registrar level – yet defenses prevented escalation beyond domain redirection.
Hours after the incident started, a person pretending to be part of the eth.limo group tricked EasyDNS support into starting an account reset.
A single point of failure in eth.limo allowed it to act like a bridge, routing requests from regular browsers to data hosted on networks such as IPFS, Arweave, and Swarm. Because its DNS setup uses wildcards, countless .eth addresses rely on the same infrastructure – making them vulnerable when one part fails.
Stopping the damage came down to DNS Security Extensions – called DNSSEC by many. Not through speed, but through verification: it checks DNS replies with digital signatures. Without access to the correct private keys, the hacker’s fake entries could not pass these tests. Because validation failed, devices refused the corrupted data, showing failures rather than loading harmful pages.
Surprisingly, EasyDNS spoke out after the event, calling it their initial customer-targeted social engineering success in almost thirty years. Following this, improvements to internal procedures are underway. Instead of old methods, eth.limo will shift to a tighter system – one without recovery pathways. That change aims to block repeat incidents.
Most recent cases show similar patterns across decentralized services. Though blockchains themselves stay distributed and protected, the websites people actually visit run on standard domain setups. These entry points open doors hackers are now using more frequently. Instead of breaking encryption, they shift traffic by manipulating DNS records. Users get sent elsewhere without noticing – sometimes losing assets quickly.
Security layers matter more than ever, shown clearly by what happened with eth.limo.
Read the original article:
