Hacker Posed as Ankr Employee To Phish Polygon and Fantom Users

The hacker tricked customer service for Ankr’s DNS provider into giving them access to Ankr’s domain registrar

article-image

Source: Shutterstock

share

key takeaways

  • The companies assert no funds were stolen, though they cannot tell for sure
  • The hack comes as Polygon announced a partnership with Meta to bring NFTs to Facebook

A hacker produced a phishing pop-up on Polygon and Fantom this morning warning users their funds were at risk and urging them to enter their private account keys. 

The hacker accessed Polygon and Fantom’s remote procedure call (RPC) interfaces through the Web3 infrastructure platform Ankr by tricking a third party domain name system (DNS) provider into giving the hacker access to Polygon and Fantom’s domains.

Ankr’s DNS is hosted on a web service named Gandi, and its customer support has a section for clients who want to change the administrator’s email for a domain.

Customer service communication at Gandi | Source: Ankr

Posing as an Ankr employee, the hacker sent Gandi a fake identity card and convinced the platform’s customer support service to change the email address for the domain registrar account from Ankr’s to the hacker’s Hotmail account.

Ankr is “still trying to understand what [Gandi] accepted as proof for this change,” Peter Stewart, integration manager at Ankr, said.

Ankr was able to regain control of the DNS within six hours of the attack. Sources at Polygon and Ankr told Blockworks that no user funds were compromised, but also conceded they cannot conclusively determine whether any users fell victim to the phishing attack.

Loading Tweet..

“DNS is unfortunately still a centralized point of failure in the internet,” Ankr co-founder Ryan Fang told Blockworks via Telegram. 

Fang said Ankr will continue to work with Gandi, but it will ask its DNS providers to use two-factor authentication moving forward.

The phishing attack comes as Polygon announced a partnership with Meta to bring NFTs to Facebook — and as NFT (non-fungible token) sales reach their lowest point in a year, according to the blockchain research platform Dune.

“It was a third party outage that does not affect Polygon in any way. Meta is not using that third party either,” Mudit Gupta, chief information security officer at Polygon, told Blockworks.

Meta did not immediately respond to a request for comment.


Start your day with top crypto insights from David Canellis and Katherine Ross. Subscribe to the Empire newsletter.

Explore the growing intersection between crypto, macroeconomics, policy and finance with Ben Strack, Casey Wagner and Felix Jauvin. Subscribe to the Forward Guidance newsletter.

Get alpha directly in your inbox with the 0xResearch newsletter — market highlights, charts, degen trade ideas, governance updates, and more.

The Lightspeed newsletter is all things Solana, in your inbox, every day. Subscribe to daily Solana news from Jack Kubinec and Jeff Albus.

Tags

Upcoming Events

Javits Center North | 445 11th Ave

Tues - Thurs, March 18 - 20, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

kamino cover.jpg

Research

Kamino has solidified its position as the leading money market on Solana and is emerging as a DeFi bluechip. Although DeFi competition is fierce, Kamino has kept iterating on its product to provide the best-in-class UX, paired with a robust risk management framework and battle-tested infrastructure. Given the rollout of Kamino Lend V2, the protocol may scale aggressively over the coming months, penetrating previously untapped markets in Solana DeFi.

article-image

August’s annual headline figure came in at 2.3% after an upward revision Thursday, so things are moving in the right direction 

article-image

MSTR’s stock price was roughly $248 at 2 pm ET Thursday

article-image

Ever since rates came off zero and fiscal deficits exploded, markets have started paying close attention to how the government is funding itself

article-image

Solana memecoins are collectively at an all-time high

article-image

Optimistic rollups like Optimism, Arbitrum and Base are seeing rapid adoption relative to zk rollups

article-image

Coinbase’s final total for Q3: $331 billion, the equivalent of 15% of the total crypto market cap at the time