DNS Attack on OpenEden. Wallets at Risk

Hackers hijacked OpenEden’s DNS, redirecting users to fake sites draining crypto wallets.

DNS Attack on OpenEden. Wallets at Risk

On February 16, OpenEden announced that the DNS system for its main website and user portal had been compromised. This created a serious risk for anyone attempting to access the platform through a web browser and connect their crypto wallets.

The Singapore-based company warned users on X not to visit the domains openeden.com and portal.openeden.com. It emphasized that all reserve assets remain secure and can be independently verified through the Chainlink Proof of Reserve mechanism. However, merely visiting the compromised website and interacting with it could result in the loss of funds from a connected wallet.

The attack involved the takeover of DNS records—the internet system that translates domain names into IP addresses. In practice, users entering the official website address were unknowingly redirected to servers controlled by the attackers. These fake websites closely resembled the original and prompted users to connect their wallets. Victims were then asked to sign transactions which, in reality, transferred tokens directly to wallets controlled by the hackers.

OpenEden clarified that the attack did not affect its smart contracts or reserve custody systems. The TBILL and USDO tokens remain secured in their respective vaults, and the assets backing them can still be verified through Chainlink.

The incident has raised significant concerns, as OpenEden is a major issuer of tokenized real-world assets and operates as an institutional custodian. Founded in 2022 in Singapore, the company provides access to tokenized U.S. Treasury bills through its TBILL token.

This breach is part of a broader wave of DNS attacks targeting cryptocurrency platforms. Similar incidents have seen project domains hijacked and traffic redirected to phishing websites, even though the underlying smart contracts remained untouched.

OpenEden has launched an investigation and promised further updates. It has not yet announced when secure access to its domains will be fully restored. Until then, users are advised to avoid interacting with the website and to verify reserves exclusively through official Chainlink tools.

Share