Entry_point: DNS record manipulation of the curve.fi domain
Exploit_vector: Attackers gained access to the domain registrar, rerouted the site to a malicious frontend that mimicked the UI and invoked wallet-draining transactions via phishing scripts.
Severity: Critical
Attack_steps:
Gained access to the registrar for curve.fi, changing DNS to point to attacker-controlled IPs.
Redirected user traffic to a cloned frontend containing malicious JavaScript designed to prompt wallet transactions.