Hackers hijack Ankr gateway for Polygon and Fantom networks

Quick Take

  • Ankr has suffered a DNS hijack affecting RPC endpoints for Fantom and Polygon.
  • The hack is tricking people into revealing their wallet seed phrases which can be used to drain their funds.

Ankr, a node infrastructure provider for proof-of-stake blockchains, suffered a domain name system (DNS) hijack on the RPC endpoints for Polygon and Fantom, according to a tweet by Polygon's chief information security officer Mudit Gupta. 

Gupta confirmed hackers executed a DNS exploit to take control over two links: https://polygon-rpc.com and https://rpc.ftm.tools. Ankr relied on these links to offer Remote Procedure Call (RPC), a node service used by crypto apps and wallets to connect to Polygon and Fantom blockchains.

The Ankr's RPC hijack appears to be an attempt to trick users into providing their wallet seed phrase. In today’s case, after exploiting DNS of Ankr’s RPC links, hackers were able to run fake messages telling users to reset their seed phrases on a phishing website they controlled.

Domain names system is a protocol used by all websites to help client users connect to website servers. But attackers can exploit vulnerabilities in the DNS protocol to attempt to steal funds, as seen today.

THE SCOOP

Keep up with the latest news, trends, charts and views on crypto and DeFi with a new biweekly newsletter from The Block's Frank Chaparro

By signing-up you agree to our Terms of Service and Privacy Policy
By signing-up you agree to our Terms of Service and Privacy Policy

In fact, such DNS attacks within the crypto space are on the rise. Just recently, DeFi projects like Convex Finance and Ribbon Finance, suffered from similar DNS vulnerabilities.

Ankr's twitter account posted that it's "investigating some reported issues." 

This is a breaking story and will be updated.


© 2023 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

About Authors

Osato is a news reporter at The Block as part of the crypto ecosystems team that focuses on DAO governance, staking, blockchain layers, and DeFi. He was previously a news reporter at Cointelegraph. Based in Lagos, Nigeria, he enjoys crosswords, poker, and attempting to beat his Scrabble high score. Follow him on Twitter at @OsatoNomayo.
Vishal Chawla is The Block’s crypto ecosystems editor and has spent over six years covering tech protocols, cybersecurity, artificial intelligence and cloud computing. Vishal likes to delve deep into blockchain intricacies to ensure readers are well-informed about the continuously evolving crypto landscape. He is also a staunch advocate for rigorous security practices in the space. Before joining The Block, Vishal held positions at IDG ComputerWorld, CIO, and Crypto Briefing. He can be reached on Twitter at @vishal4c and via email at [email protected]