Squarespace Domains Become Web3 Attack Vector

Urgent Cyber Threat: Domains Hijacked to Steal Crypto Assets in Web3 Sector

Image illustrating a sophisticated cyberattack targeting Web3 companies, showing digital assets vulnerable to theft through domain hijacking.
A visual representation of the escalating cyber threat within the Web3 space.

The burgeoning world of Web3, despite its promise of decentralization and enhanced security through blockchain technology, is currently facing a significant and alarming cyber threat. A growing number of Web3 companies are reporting that their critical domains, many of which were registered or transferred to Squarespace (NYSE: SQSP), have been successfully hijacked by malicious actors. This sophisticated attack vector targets the very foundation of digital identity and trust, with the explicit aim of stealing valuable crypto assets and undermining user confidence.

This escalating crisis highlights a critical vulnerability in the interconnected digital infrastructure that underpins the decentralized web. While Web3 projects often focus on the security of their smart contracts and blockchain protocols, the reliance on traditional centralized services like domain registrars presents an undeniable attack surface. The current wave of incidents serves as a stark reminder that a chain is only as strong as its weakest link, and in this case, that link appears to be domain management and account security.

The Alarming Trend: Web3 Domains Under Siege

Reports began surfacing yesterday and have accelerated today, indicating a coordinated or widespread attack campaign. Numerous Web3 entities, ranging from prominent projects to newer startups, have discovered unauthorized changes to their domain settings. The common thread among many of these victims is their association with Squarespace, particularly those whose domains originated from Google Domains before its acquisition by Squarespace last year.

The implications of such domain hijacking are profound. Control over a company’s primary domain grants attackers an incredibly powerful tool. It allows them to intercept legitimate communications, redirect website traffic, and, most critically, impersonate the legitimate entity to deceive users and initiate malicious transactions. In an ecosystem where trust is paramount and asset ownership is tied to digital identities, this type of breach can lead to catastrophic financial losses and severe reputational damage.

Unstoppable Domains: A High-Profile Victim Emerges

Among the victims is Unstoppable Domains, a leading provider of Web3 domains that serve as user-owned digital identities linked to crypto wallets. Earlier today, Unstoppable Domains issued a public warning on X (formerly Twitter), confirming its status as a target of this attack. The company expressed grave concern over the potential for attackers to spoof their corporate identity in email communications, leading to highly convincing phishing attempts. Even more alarmingly, there is a significant risk that threat actors could leverage their hijacked domain access to create sophisticated fake websites designed to lure users into inadvertently draining their crypto wallets. For a company whose core business is digital identity and domain ownership, such an attack represents a direct assault on its fundamental value proposition and the trust of its user base.

The incident involving Unstoppable Domains underscores the severity of this ongoing campaign. As a foundational service in the Web3 space, its compromise sends ripples of concern throughout the entire ecosystem. Users rely on such services to securely manage their digital assets and identities, and any breach directly impacts their ability to do so safely. The potential for a fake Unstoppable Domains website, for instance, could trick users into signing malicious transactions or revealing their private keys, leading to irreversible loss of funds.

Unpacking the Attack Vector: How Threat Actors Operate

To understand the mechanics of this sophisticated domain hijacking scheme, it’s crucial to look at the insights provided by cybersecurity experts. Michael Coates, COO and CISO at Coinlist, offered a detailed explanation of the attack methodology, shedding light on the alarming simplicity and effectiveness of the strategy:

1. The attackers are gaining unauthorized access to SquareSpace and adjusting settings to forward all email to an attacker’s email address at a http://proton.me address
2. The attacker then initiates password resets at important third party services such as chat services and custodians. These resets are targeting specific individuals the attackers believe have admin access to the accounts.
3. If the email forwarding attack was successful then the password resets would be sent to the attacker, they’d be able to extract the password reset urls and then take over the third party services.
4. Attackers would then use all of this access to either directly drain funds or modify websites to include malicious code to compromise users.

The Anatomy of a Domain Hijack: A Four-Step Process

Coates’ explanation reveals a multi-stage attack that leverages initial unauthorized access to gain deeper control over critical infrastructure:

  1. Unauthorized Access to Squarespace Accounts and Email Forwarding Manipulation: The initial, and most critical, step involves attackers gaining unauthorized entry into the Squarespace accounts managing the victim companies’ domains. While the exact method of initial compromise remains “unclear” at this time – it could involve sophisticated phishing campaigns targeting employees, credential stuffing, exploiting weak passwords, or even a zero-day vulnerability in Squarespace’s system – the result is devastating. Once inside, the attackers immediately alter the domain’s email settings. They configure all incoming emails for the compromised domain to be forwarded to an attacker-controlled address, specifically noted to be at ‘proton.me’. This email interception is the linchpin of the entire operation, effectively blinding the legitimate domain owner to subsequent malicious activities and providing the attacker with a stream of sensitive communications.
  2. Targeted Password Resets for Key Third-Party Services: With email forwarding established, the attackers move to the second phase: exploiting their newfound control to compromise other critical services. They initiate password reset requests for important third-party platforms that the Web3 companies rely on. These services often include internal chat systems (like Slack or Discord), customer support portals, and crucially, custodial services that manage significant crypto assets. The attackers are highly selective, targeting password resets for specific individuals believed to hold administrative privileges or access to high-value accounts. This precision maximizes their chances of quickly escalating their access.
  3. Exploiting Intercepted Resets to Gain Control: This is where the email forwarding comes into full effect. When password reset emails are sent from these third-party services, they are not delivered to the legitimate administrators. Instead, thanks to the malicious forwarding rule, they land directly in the attacker’s ‘proton.me’ inbox. The attackers can then extract the password reset URLs contained within these emails, allowing them to bypass security protocols and set new passwords for the targeted third-party accounts. This grants them unfettered access to internal communications, customer data, and potentially, direct control over crypto asset management platforms.
  4. Monetization: Direct Fund Drainage or Malicious Website Modification: The final stage is the ultimate goal: monetization of the compromise. With extensive access to various internal and external services, attackers have two primary avenues. They can either directly drain crypto funds from custodial accounts or wallets they’ve gained access to. Alternatively, they can modify the victim company’s website (if they’ve gained control of web hosting credentials via the same methods) to inject malicious code. This malicious code might include sophisticated wallet drainers, phishing forms designed to steal user credentials, or redirects to attacker-controlled sites, all aimed at compromising end-users and siphoning off their crypto assets.

The Squarespace Connection: From Google Domains to a Critical Vulnerability

Many in the Web3 community might find it surprising that a significant number of cryptocurrency companies utilize Squarespace for their domain registrations. This phenomenon is largely attributable to a major industry shift that occurred last year: Google’s decision to exit the domain name registration business. In a move that sent ripples through the domain industry, Squarespace completed its acquisition of Google Domains’ customer accounts and related assets in September 2023. This transaction saw millions of domains automatically migrated from Google Domains to Squarespace’s platform.

For many Web3 companies, who likely initially registered their domains with Google Domains due to its reputable service and integration with other Google services, this transition to Squarespace was automatic and, for some, perhaps unnoticed or simply accepted. This consolidation of domain management under a single new provider, while seemingly a straightforward business transaction, inadvertently created a critical single point of failure or an enlarged attack surface. Threat actors may have identified this migration as an opportunity, potentially exploiting unfamiliarity with Squarespace’s security features, or even vulnerabilities arising from the transition process itself, to launch their attacks. This historical context is crucial for understanding why so many Web3 entities are now finding their domains compromised through a common registrar.

Security Measures: Registry Lock and Beyond

In the realm of domain security, features like “Registry Lock” (sometimes referred to as “Registrar Lock” or “ClientHold”) are often touted as the ultimate defense against unauthorized domain transfers. Registry Lock, when enabled, prevents any changes to a domain’s registration information, including transfers, deletions, or modifications to nameservers, unless an additional, out-of-band verification process is completed with the registry itself. This typically involves manual confirmation via a verified contact or even physical documentation, adding an extremely high barrier to entry for unauthorized modifications.

However, the current wave of attacks illustrates a critical nuance: while Unstoppable Domains did not have Verisign Registry Lock on its domain, it’s highly probable that this specific security measure might not have prevented the type of email forwarding and account takeover attack currently being observed. This is because the attackers are not primarily focused on initiating an unauthorized *domain transfer*. Instead, their initial objective is to gain unauthorized *access to the domain owner’s account at the registrar (Squarespace)*. Once they control this account, they can modify settings like email forwarding, initiate password resets for linked services, and potentially alter DNS records, all without triggering the domain transfer protections offered by Registry Lock.

This situation underscores the importance of a multi-layered security approach. While Registry Lock is vital for protecting against domain transfers, companies must also implement robust security protocols for their registrar accounts themselves. This includes mandatory Multi-Factor Authentication (MFA) for all account logins, especially those with administrative privileges, using hardware security keys (e.g., FIDO2/WebAuthn) wherever possible, strong and unique passwords, and regular security audits of all critical service accounts. Employee security awareness training, focusing on identifying phishing attempts and social engineering tactics, is also paramount to prevent the initial compromise that can lead to such devastating consequences.

The Broader Ramifications for Web3 Security

This wave of domain hijacking attacks has far-reaching implications for the entire Web3 ecosystem, extending beyond immediate financial losses:

  • Eroding Trust: Trust is the bedrock of the decentralized future Web3 envisions. When fundamental components like domain identity are compromised, it severely shakes user and investor confidence. This erosion of trust can slow adoption and create a perception of insecurity around Web3 technologies, hindering their mainstream acceptance.
  • Centralization Risks in a Decentralized World: The irony of this attack is striking. Web3 aims to minimize reliance on centralized entities, yet critical infrastructure like domain name systems (DNS) remains largely centralized. The fact that a single point of failure (a domain registrar like Squarespace) can expose numerous Web3 projects highlights the inherent centralization risks that still persist, even within decentralized ecosystems.
  • Increased Regulatory Scrutiny: As the crypto market matures, regulators worldwide are increasingly focused on consumer protection and market integrity. Incidents of widespread theft and security breaches due to domain hijacking will undoubtedly attract more attention from regulatory bodies, potentially leading to stricter compliance requirements and a more challenging operating environment for Web3 companies.
  • Sophistication of Attack Vectors: These attacks demonstrate the evolving sophistication of threat actors targeting the crypto space. They are no longer just looking for vulnerabilities in smart contracts but are exploiting traditional cybersecurity weaknesses (like account takeovers and email forwarding) to achieve their goals, illustrating the need for holistic security strategies that span both blockchain and conventional IT infrastructure.

Urgent Call to Action: Protecting Your Digital Assets

In light of these pressing threats, immediate action is required from both Web3 companies and individual users to bolster their defenses:

For Web3 Companies:

  • Implement Strong Multi-Factor Authentication (MFA): This is non-negotiable for all critical accounts, especially those managing domain registrations, email services, and custodial crypto assets. Hardware security keys offer the strongest protection.
  • Regularly Audit Domain Settings: Periodically review all domain registrar settings, including nameservers, DNS records, and email forwarding rules, to detect any unauthorized modifications promptly.
  • Isolate Critical Accounts: Use dedicated, highly secured email addresses and unique login credentials for domain registrar accounts that are not used for general correspondence.
  • Employee Security Training: Educate employees about advanced phishing techniques, social engineering, and the importance of reporting suspicious activity immediately.
  • Incident Response Plan: Develop and regularly test a comprehensive incident response plan specifically for domain compromise and account takeover scenarios.
  • Consider Specialized DNS Security: Explore advanced DNS security services that offer additional layers of protection against various forms of DNS manipulation.

For Individual Users:

  • Extreme Vigilance: Always be suspicious of unsolicited emails, even if they appear to come from legitimate Web3 services. Verify sender authenticity through alternative channels.
  • Verify URLs Manually: Before interacting with any Web3 website or connecting your wallet, double-check the URL in your browser’s address bar. Malicious sites often use subtle misspellings.
  • Use Hardware Wallets: For storing significant crypto assets, hardware wallets provide the best protection against online theft.
  • Educate Yourself: Stay informed about common attack vectors and best security practices in the Web3 space.

Squarespace’s Response and Ongoing Developments

The severity and widespread nature of this incident demand a robust and transparent response from Squarespace. We have reached out to Squarespace for official comment regarding these domain hijacking reports, seeking clarification on the root cause of the unauthorized access, the number of affected accounts, and the measures being implemented to mitigate the ongoing threat and prevent future occurrences. As the situation is fluid and evolving, we anticipate a detailed statement from the company outlining their investigation and remediation efforts.

The Web3 community, along with cybersecurity professionals, will be closely monitoring Squarespace’s response and any further developments. Transparency and swift action will be crucial in restoring confidence among affected companies and their users. This incident also serves as a critical test for Squarespace’s security infrastructure and its ability to protect high-value customers in a rapidly evolving threat landscape.

Conclusion: Heightened Vigilance is the New Standard

The ongoing domain hijacking attacks targeting Web3 companies through Squarespace underscore a critical reality: the security perimeter of digital assets extends far beyond the blockchain itself. While Web3 technologies promise decentralization and enhanced cryptographic security, their reliance on conventional internet infrastructure like the Domain Name System (DNS) introduces vulnerabilities that threat actors are keen to exploit. This wave of attacks, meticulously detailed by experts like Michael Coates, demonstrates a sophisticated understanding of interconnected systems, leveraging initial account compromise to achieve widespread disruption and financial theft.

This incident serves as a clarion call for heightened vigilance and a fundamental re-evaluation of security practices across the entire Web3 ecosystem. Companies and individuals alike must adopt a proactive, multi-layered approach to security, recognizing that traditional cyber threats can have devastating consequences in the world of decentralized finance. Robust MFA, continuous monitoring of critical infrastructure, and comprehensive employee training are no longer optional but essential safeguards against a persistent and evolving threat landscape. The future of Web3 depends on our collective ability to secure every link in the digital chain, from the blockchain to the very domains that define our online presence.