Steakhouse postmortem reveals DNS hijack caused by registrar 2FA bypass

ambcryptoPubblicato 2026-04-10Pubblicato ultima volta 2026-04-10

Introduzione

Steakhouse's postmortem of a 30 March security incident reveals that attackers hijacked its domain through a social engineering attack on its registrar, OVHcloud. The attacker impersonated the account owner, convinced support to disable hardware-based two-factor authentication, and took full control of the account. This allowed them to redirect DNS to a phishing site with a wallet drainer for about four hours. No user funds were lost, as on-chain systems remained secure, and wallet protections quickly detected the fake site. The breach underscores the risk of off-chain infrastructure vulnerabilities and over-reliance on a single registrar. Steakhouse has since migrated registrars, enhanced DNS monitoring, and implemented stricter domain security controls.

A postmortem from Steakhouse has shed new light on a 30 March security incident. Attackers briefly hijacked its domain to serve a phishing site, exposing a critical weakness in off-chain infrastructure rather than on-chain systems.

The team confirmed that the attack stemmed from a successful social engineering attempt targeting its domain registrar, OVHcloud. This allowed the attacker to bypass two-factor authentication and take control of DNS records.

Social engineering led to full account takeover

According to the report, the attacker contacted the registrar’s support desk, impersonated the account owner, and convinced a support agent to remove hardware-based two-factor authentication.

Once access was granted, the attacker rapidly executed a series of automated actions. This included deleting existing security credentials, enrolling new authentication devices, and redirecting DNS records to infrastructure under their control.

This enabled the deployment of a cloned Steakhouse website embedded with a wallet drainer, which remained intermittently accessible for roughly four hours.

Phishing site active, but funds remained safe

Despite the severity of the breach, Steakhouse stated that no user funds were lost and no malicious transactions were confirmed.

The compromise was limited to the domain layer. On-chain vaults and smart contracts, which operate independently of the frontend, were not affected. The protocol emphasized that it holds no admin keys that could access user deposits.

Browser wallet protections from providers such as MetaMask and Phantom quickly flagged the phishing site, while the team issued a public warning within 30 minutes of detecting the incident.

Postmortem highlights vendor risk and single points of failure

The report points to a key failure in Steakhouse’s security assumptions: reliance on a single registrar whose support processes could override hardware-based protections.

The ability to disable two-factor authentication via a phone call, without robust out-of-band verification, effectively turned a credential leak into a full account takeover.

Steakhouse acknowledged that it had not adequately assessed this risk, describing the registrar as a “single point of failure” in its infrastructure.

Off-chain vulnerabilities remain a weak link

The incident underscores a broader issue in crypto security — that strong on-chain protections do not eliminate risks in surrounding infrastructure.

While smart contracts and vaults remained secure, control over DNS allowed the attacker to target users through phishing, a method increasingly common in the ecosystem.

The attack also involved tools consistent with “drainer-as-a-service” operations, highlighting how attackers continue to combine social engineering with ready-made exploit kits.

Security upgrades and next steps

Following the incident, Steakhouse has migrated to a more secure registrar. It implemented continuous DNS monitoring, rotated credentials, and launched a broader review of vendor security practices.

The team also introduced stricter controls for domain management, including hardware key enforcement and registrar-level locks.


Final Summary

  • Steakhouse’s postmortem reveals that a registrar-level 2FA bypass enabled a DNS hijack, exposing users to phishing despite secure on-chain systems.
  • The incident highlights how off-chain infrastructure and vendor security remain critical vulnerabilities in crypto ecosystems.

Domande pertinenti

QWhat was the root cause of the security incident at Steakhouse on March 30th?

AThe root cause was a successful social engineering attack targeting their domain registrar, OVHcloud, which allowed the attacker to bypass two-factor authentication and take control of the DNS records.

QHow did the attacker manage to bypass the two-factor authentication on the registrar account?

AThe attacker impersonated the account owner, contacted the registrar's support desk, and convinced a support agent to remove the hardware-based two-factor authentication protection.

QWere any user funds lost as a result of this DNS hijacking and phishing attack?

ANo, Steakhouse confirmed that no user funds were lost and no malicious transactions were confirmed. The on-chain vaults and smart contracts were not compromised.

QWhat key security failure did the postmortem report identify in Steakhouse's infrastructure?

AThe report identified the reliance on a single registrar, whose support processes could override hardware-based protections, as a critical 'single point of failure' that was not adequately assessed.

QWhat security measures did Steakhouse implement after the incident to prevent future attacks?

ASteakhouse migrated to a more secure registrar, implemented continuous DNS monitoring, rotated credentials, enforced stricter domain management controls (like hardware keys), and launched a broader review of vendor security practices.

Letture associate

'Backstabbing' or 'Win-Win'? How Likely Is TradeXYZ to Break Away from Hyperliquid and Go Solo?

The article discusses the growing debate over whether TradeXYZ, which dominates Hyperliquid's HIP-3 market with over 90% of its volume, might break away to build its own independent trading platform. This possibility is fueled by TradeXYZ's immense market influence and the common industry trend of successful projects seeking more control and profit capture. Key arguments for a potential split include TradeXYZ's overwhelming contribution to Hyperliquid's metrics and the financial incentive to retain all transaction fees, as it currently splits them 50/50 with Hyperliquid. The piece draws parallels to other cases, like Anthropic's "Claude Code" competing with its former partner Cursor, suggesting "betrayal" can occur when business leverage shifts. However, strong counterarguments suggest a split is unlikely or would be detrimental. TradeXYZ relies on Hyperliquid's high-performance infrastructure and its platform as a primary user acquisition channel. Building a comparable system would be challenging. Furthermore, the founders of both projects share a history of trust and mutual admiration. The analysis concludes that a separation would likely be a lose-lose scenario: Hyperliquid would lose a major growth narrative and trading volume, while TradeXYZ would face technical hurdles, user migration issues, and reputational damage, potentially allowing competitors to seize market share. The most rational path is seen as continued collaboration, with TradeXYZ potentially negotiating better terms while leveraging Hyperliquid's established strengths.

marsbit4 min fa

'Backstabbing' or 'Win-Win'? How Likely Is TradeXYZ to Break Away from Hyperliquid and Go Solo?

marsbit4 min fa

The Artificial Intelligence Economy Could Accelerate the Establishment of Dominance for Dollar-Pegged Stablecoins

Economists from the ASEAN+3 Macroeconomic Research Office (AMRO) suggest that the winner in the artificial intelligence (AI) race may not be the country developing the most powerful AI model, but the one whose currency underpins these models and their infrastructure. Their thesis outlines a potential cycle where AI-related costs—such as energy for data centers, infrastructure, and usage fees—are denominated in U.S. dollars. As AI grows into a massive industry, this could significantly increase global demand for U.S. dollar liquidity (first channel of dollar dominance). A second channel involves the currency used for payments between AI agents, expected to become widespread in logistics, inventory, and treasury management. Dollar-pegged stablecoins could provide the programmable settlements required for such agent commerce. These two channels may converge, creating a self-reinforcing "dollar loop" where AI computational payments are settled in stablecoins. Stablecoins could gain an early advantage over alternatives like CBDCs due to existing network effects, further entrenching dollar dominance. This would also boost demand for U.S. Treasury bonds used as collateral for stablecoin reserves. The report warns ASEAN+3 nations of over-reliance on this dollar loop and suggests developing regional data centers and tokenized money based on local currencies to participate in the AI economy without reinforcing dollar dependency.

cryptonews.ru7 min fa

The Artificial Intelligence Economy Could Accelerate the Establishment of Dominance for Dollar-Pegged Stablecoins

cryptonews.ru7 min fa

Base Claims Its Distribution Advantage Can Outlast Robinhood Chain's Initial Surge

Base, a layer-2 blockchain, argues that its established distribution network will outlast Robinhood Chain's initial popularity surge. While Robinhood Chain quickly attracted 230,000 daily active users and over $9 billion in DEX volume (primarily from meme coins) shortly after launch, its core feature of tokenized stocks saw minimal use. Base acknowledged shortcomings in focusing on social blockchain products and lagging in areas like perpetual contracts, predictions markets, and on-chain tokenized stocks—a move Robinhood got right. In response, Base highlights its nearly three-year head start in building infrastructure. It emphasizes its x402 payment protocol, which has processed 187.8 million agent payments, its $3.9 billion in stablecoin deposits (mostly USDC), and its integration with partners like Visa, Shopify, and JPMorgan for institutional and merchant settlements. Base contends these capabilities for corporate payments and stablecoin liquidity represent a more durable and defensible ecosystem than Robinhood's retail trading metrics. Coinbase plans to launch its own on-chain, share-backed tokenized stocks on Base, which would directly challenge Robinhood's key differentiating feature. Base's strategy bets that its deep-rooted distribution and institutional partnerships will prove harder to overcome than Robinhood's early, meme-driven volume, which may fade after the initial launch hype.

cryptonews.ru9 min fa

Base Claims Its Distribution Advantage Can Outlast Robinhood Chain's Initial Surge

cryptonews.ru9 min fa

Trading

Spot
活动图片