Steakhouse postmortem reveals DNS hijack caused by registrar 2FA bypass

ambcryptoPublicado a 2026-04-10Actualizado a 2026-04-10

Resumen

Steakhouse's postmortem of a 30 March security incident reveals that attackers hijacked its domain through a social engineering attack on its registrar, OVHcloud. The attacker impersonated the account owner, convinced support to disable hardware-based two-factor authentication, and took full control of the account. This allowed them to redirect DNS to a phishing site with a wallet drainer for about four hours. No user funds were lost, as on-chain systems remained secure, and wallet protections quickly detected the fake site. The breach underscores the risk of off-chain infrastructure vulnerabilities and over-reliance on a single registrar. Steakhouse has since migrated registrars, enhanced DNS monitoring, and implemented stricter domain security controls.

A postmortem from Steakhouse has shed new light on a 30 March security incident. Attackers briefly hijacked its domain to serve a phishing site, exposing a critical weakness in off-chain infrastructure rather than on-chain systems.

The team confirmed that the attack stemmed from a successful social engineering attempt targeting its domain registrar, OVHcloud. This allowed the attacker to bypass two-factor authentication and take control of DNS records.

Social engineering led to full account takeover

According to the report, the attacker contacted the registrar’s support desk, impersonated the account owner, and convinced a support agent to remove hardware-based two-factor authentication.

Once access was granted, the attacker rapidly executed a series of automated actions. This included deleting existing security credentials, enrolling new authentication devices, and redirecting DNS records to infrastructure under their control.

This enabled the deployment of a cloned Steakhouse website embedded with a wallet drainer, which remained intermittently accessible for roughly four hours.

Phishing site active, but funds remained safe

Despite the severity of the breach, Steakhouse stated that no user funds were lost and no malicious transactions were confirmed.

The compromise was limited to the domain layer. On-chain vaults and smart contracts, which operate independently of the frontend, were not affected. The protocol emphasized that it holds no admin keys that could access user deposits.

Browser wallet protections from providers such as MetaMask and Phantom quickly flagged the phishing site, while the team issued a public warning within 30 minutes of detecting the incident.

Postmortem highlights vendor risk and single points of failure

The report points to a key failure in Steakhouse’s security assumptions: reliance on a single registrar whose support processes could override hardware-based protections.

The ability to disable two-factor authentication via a phone call, without robust out-of-band verification, effectively turned a credential leak into a full account takeover.

Steakhouse acknowledged that it had not adequately assessed this risk, describing the registrar as a “single point of failure” in its infrastructure.

Off-chain vulnerabilities remain a weak link

The incident underscores a broader issue in crypto security — that strong on-chain protections do not eliminate risks in surrounding infrastructure.

While smart contracts and vaults remained secure, control over DNS allowed the attacker to target users through phishing, a method increasingly common in the ecosystem.

The attack also involved tools consistent with “drainer-as-a-service” operations, highlighting how attackers continue to combine social engineering with ready-made exploit kits.

Security upgrades and next steps

Following the incident, Steakhouse has migrated to a more secure registrar. It implemented continuous DNS monitoring, rotated credentials, and launched a broader review of vendor security practices.

The team also introduced stricter controls for domain management, including hardware key enforcement and registrar-level locks.


Final Summary

  • Steakhouse’s postmortem reveals that a registrar-level 2FA bypass enabled a DNS hijack, exposing users to phishing despite secure on-chain systems.
  • The incident highlights how off-chain infrastructure and vendor security remain critical vulnerabilities in crypto ecosystems.

Preguntas relacionadas

QWhat was the root cause of the security incident at Steakhouse on March 30th?

AThe root cause was a successful social engineering attack targeting their domain registrar, OVHcloud, which allowed the attacker to bypass two-factor authentication and take control of the DNS records.

QHow did the attacker manage to bypass the two-factor authentication on the registrar account?

AThe attacker impersonated the account owner, contacted the registrar's support desk, and convinced a support agent to remove the hardware-based two-factor authentication protection.

QWere any user funds lost as a result of this DNS hijacking and phishing attack?

ANo, Steakhouse confirmed that no user funds were lost and no malicious transactions were confirmed. The on-chain vaults and smart contracts were not compromised.

QWhat key security failure did the postmortem report identify in Steakhouse's infrastructure?

AThe report identified the reliance on a single registrar, whose support processes could override hardware-based protections, as a critical 'single point of failure' that was not adequately assessed.

QWhat security measures did Steakhouse implement after the incident to prevent future attacks?

ASteakhouse migrated to a more secure registrar, implemented continuous DNS monitoring, rotated credentials, enforced stricter domain management controls (like hardware keys), and launched a broader review of vendor security practices.

Lecturas Relacionadas

"Teletubbies" robots hacen limpieza a domicilio, 200 yuanes/hora, pura inteligencia *artificial*

La compañía de robótica Tau Robotics, con sede en San Francisco, ha presentado su nuevo servicio de limpieza doméstica utilizando robots humanoides teleoperados. Bautizados cariñosamente como "Teletubbies" por su antena similar a un router Wi-Fi en la cabeza, estos robots, llamados Chelsea, Elon y Tony, realizan tareas como limpiar cocinas, baños, recoger basura y trapear pisos. La gran revelación, y decepción para algunos, es que las demostraciones mostradas son operadas por control remoto en tiempo real ("inteligencia artificial 100% humana"). La empresa defiende este enfoque como una solución práctica para cerrar la brecha tecnológica actual, permitiendo la recolección de datos del mundo real para eventualmente desarrollar autonomía completa, similar al "modo sombra" en los coches autónomos. El servicio, disponible por invitación en el área de la Bahía de San Francisco, cuesta 30 dólares (unos 200 yuanes) por hora, un precio competitivo frente a los servicios de limpieza humana en EE.UU. El artículo analiza los desafíos de introducir robots humanoides en hogares, comparando el enfoque estadounidense con el chino, que prioriza entornos industriales más controlados. Se argumenta que la forma humanoide facilita la teleoperación intuitiva y podría ofrecer un valor emocional único, aunque su necesidad funcional frente a robots con ruedas sigue siendo objeto de debate.

marsbitHace 4 min(s)

"Teletubbies" robots hacen limpieza a domicilio, 200 yuanes/hora, pura inteligencia *artificial*

marsbitHace 4 min(s)

Qualcomm: La fiebre de la IA se desvanece, ¿cuándo saldrá el mercado de teléfonos de la niebla?

El 30 de julio de 2026, Qualcomm publicó sus resultados del tercer trimestre del año fiscal 2026. Los ingresos fueron de 9,950 millones de dólares, un 4% menos que el año anterior, superando las expectativas del mercado. Sin embargo, el margen bruto cayó al 53,1%, por debajo de lo previsto, debido al aumento de costes en fabricación, ensamblaje y memoria. El negocio principal de chips para teléfonos registró una fuerte caída del 19,6%, alcanzando los 5,090 millones de dólares. Esto se debió a una disminución general del 11% en los envíos de teléfonos Android y a que los fabricantes optaron por usar plataformas anteriores para reducir costes. En contraste, el segmento automotriz creció un 61%, impulsado por los sistemas de infoentretenimiento, y el de IoT aumentó un 9%. La compañía prevé unos ingresos para el próximo trimestre entre 9,700 y 10,500 millones de dólares, pero una ganancia por acción inferior a las expectativas. El mercado de teléfonos sigue débil y los precios de la memoria presionan los costes. Ante la debilidad de su negocio central, Qualcomm busca oportunidades en IA. Su estrategia incluye IA en dispositivos (teléfonos, PC, coches) y una importante incursión en centros de datos, con aceleradores de IA, CPU comerciales, chips personalizados y productos de conectividad. Aunque esta estrategia impulsó antes su cotización, las preocupaciones sobre el gasto en IA la han hecho retroceder. La empresa tiene el objetivo de alcanzar 15,000 millones de dólares en ingresos por centros de datos para 2029, pero por ahora, este negocio se percibe con escepticismo, mientras el mercado tradicional sigue enfrentando desafíos.

marsbitHace 52 min(s)

Qualcomm: La fiebre de la IA se desvanece, ¿cuándo saldrá el mercado de teléfonos de la niebla?

marsbitHace 52 min(s)

Explotación en Coldcard desata migración de Bitcoin, consolidación 'alcista' de cripto: Resumen del Hodler, 2 de agosto

Tras el drenaje de 90 millones de dólares en Bitcoin de usuarios de la billetera Coldcard, los pequeños "hodlers" buscaron refugio en exchanges centralizados. Las transferencias de menos de 1 BTC alcanzaron su máximo diario desde 2022, con 39.600 BTC movidos. Galaxy Research informó que los ataques al monedero hardware resultaron en pérdidas estimadas de 1.367 BTC (88,6 millones de dólares). Se insta a los usuarios a mover fondos de direcciones generadas por Coldcard debido a un fallo en la generación de semillas. Mientras tanto, el reloj de la "Clarity Act" se agota en EE.UU., con desacuerdos sobre su aplicación y los beneficios en cripto de Trump. Los informes de ganancias del segundo trimestre muestran pérdidas para Coinbase y Strategy, aunque Robinhood registró récords a pesar del descenso en ingresos por cripto. Un analista de ARK Invest señala que la industria entra en su mayor fase de consolidación, con el 80% de los ingresos concentrados en pocos protocolos, lo que considera "extremadamente alcista". La Copa del Mundo 2026 generó 20.000 millones de dólares en volumen de mercados de predicción blockchain. En cuanto a precios, Bitcoin y Ether cayeron alrededor de un 3% esta semana. Grayscale sugiere que Bitcoin pudo haber tocado fondo antes de lo habitual en su ciclo. Otras noticias incluyen: Rusia y Australia persiguen al fundador de Telegram; Pump.fun despidió empleados antes de que recibieran tokens valiosos; y un exoperador de teleprompter de Trump es acusado de usar información privilegiada para apostar.

cointelegraphHace 1 hora(s)

Explotación en Coldcard desata migración de Bitcoin, consolidación 'alcista' de cripto: Resumen del Hodler, 2 de agosto

cointelegraphHace 1 hora(s)

Trading

Spot
活动图片