TLDR Hackers impersonated an eth.limo team member to trick EasyDNS into handing over account access The attacker changed nameservers twice between 2am and 4am onTLDR Hackers impersonated an eth.limo team member to trick EasyDNS into handing over account access The attacker changed nameservers twice between 2am and 4am on

The Attack on eth.limo Shows Why Crypto Websites Are Still Vulnerable to Old-School Hacking

2026/04/20 15:38
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

TLDR

  • Hackers impersonated an eth.limo team member to trick EasyDNS into handing over account access
  • The attacker changed nameservers twice between 2am and 4am on April 18 before access was restored
  • DNSSEC blocked the attack from causing real damage by rejecting the attacker’s unsigned DNS responses
  • EasyDNS CEO publicly apologized, calling it the company’s first successful social engineering breach in 28 years
  • eth.limo will now migrate to Domainsure, a stricter platform with no account recovery option

Ethereum Name Service gateway eth.limo was hijacked on Friday night after a hacker tricked its domain registrar, EasyDNS, using a social engineering attack.

The attacker pretended to be an eth.limo team member and started an account recovery process with EasyDNS at 7:07 p.m. EDT on April 17. By 2:23 a.m. EDT on April 18, the attacker had flipped eth.limo’s nameservers to Cloudflare. They were then switched again to Namecheap at 3:57 a.m. EDT.

The Attack on eth.limo Shows Why Crypto Websites Are Still Vulnerable to Old-School Hacking

EasyDNS restored the legitimate team’s account access at 7:49 a.m. EDT, ending the roughly five-hour window of exposure.

Eth.limo acts as a gateway between regular web browsers and Ethereum Name Service domains. It covers around 2 million .eth domains, including Ethereum co-founder Vitalik Buterin’s personal blog at vitalik.eth.limo.

A successful takeover could have let the attacker redirect users of any .eth site to phishing pages. Buterin warned his followers on Friday to avoid all eth.limo URLs and pointed them to IPFS directly.

How DNSSEC Stopped the Attack

The attacker never got hold of eth.limo’s DNSSEC signing keys. Without those keys, the attacker could not produce valid cryptographic signatures.

DNS resolvers checking the new nameserver responses found they didn’t match the legitimate records. Instead of directing users to the attacker’s sites, resolvers returned error messages.

He added that no other EasyDNS customers were affected by the breach.

What Happens Next

Eth.limo will be moved to Domainsure, a service affiliated with EasyDNS that is built for enterprise and high-value clients. Domainsure has no account recovery mechanism, which closes the door that attackers used in this case.

Jeftovic said EasyDNS is still conducting an internal investigation into exactly how the attack was carried out.

This incident is part of a growing pattern. In November 2025, DNS hijacks of decentralized exchanges Aerodrome and Velodrome drained more than $700,000 from users after attackers hit registrar NameSilo and removed DNSSEC from those domains.

Stablecoin protocol Steakhouse Financial disclosed a similar breach on March 30, after OVH support staff were tricked into removing two-factor authentication from its account.

Eth.limo’s service is back online and under the original team’s control.

The post The Attack on eth.limo Shows Why Crypto Websites Are Still Vulnerable to Old-School Hacking appeared first on CoinCentral.

Market Opportunity
Ethereum Logo
Ethereum Price(ETH)
$2,316.32
$2,316.32$2,316.32
-0.62%
USD
Ethereum (ETH) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!