Back to dashboard
Sunday, September 14, 2025 at 19:00 UTC

Aerodrome Frontend

DNS hijack injected malicious swap router.

Partial
Funds stolen
$7.20M
Recovered
$2.10M29%
Still outstanding
$5.10M
Chain
Base
Category
DeFi
Attack vector
Frontend Hijack
Reported by
CertiK
Incident ID
h2025-4

Exploit & recovery timeline

  1. Sep 14, 2025 · 17:00 UTC
    Attack preparation

    Attacker wallets funded and staged ahead of the frontend hijack exploit against Aerodrome Frontend.

  2. Sep 14, 2025 · 19:00 UTC
    Exploit executed

    $7.2M drained from Aerodrome Frontend on Base via Frontend Hijack.

  3. Sep 14, 2025 · 20:00 UTC
    Detected by CertiK

    CertiK flagged the anomalous transactions and published an initial alert.

  4. Sep 14, 2025 · 23:00 UTC
    Protocol response

    Aerodrome Frontend paused affected contracts or withdrawals and began tracing outbound flows.

  5. Sep 15, 2025 · 19:00 UTC
    Funds traced

    Stolen assets followed through mixers, bridges, and exchange deposit addresses.

  6. Sep 21, 2025 · 19:00 UTC
    Partial recovery

    $2.1M of $7.2M recovered (29%); the remainder is still unaccounted for.

  7. Oct 14, 2025 · 19:00 UTC
    Investigation continues

    Remaining funds monitored across chains with exchange partners notified.