DNS hijack injected malicious swap router.
Attacker wallets funded and staged ahead of the frontend hijack exploit against Aerodrome Frontend.
$7.2M drained from Aerodrome Frontend on Base via Frontend Hijack.
CertiK flagged the anomalous transactions and published an initial alert.
Aerodrome Frontend paused affected contracts or withdrawals and began tracing outbound flows.
Stolen assets followed through mixers, bridges, and exchange deposit addresses.
$2.1M of $7.2M recovered (29%); the remainder is still unaccounted for.
Remaining funds monitored across chains with exchange partners notified.