DNS hijack served malicious approval prompts.
Attacker wallets funded and staged ahead of the frontend hijack exploit against AvaxKingdom.
$4.8M drained from AvaxKingdom on Avalanche via Frontend Hijack.
CertiK flagged the anomalous transactions and published an initial alert.
AvaxKingdom paused affected contracts or withdrawals and began tracing outbound flows.
Stolen assets followed through mixers, bridges, and exchange deposit addresses.
No assets recovered; losses absorbed by the protocol, insurers, or users.