Critical attack hits 2 million .eth domains, DNSSEC saves users
A social-engineering attack on April 17, 2026 targeted eth.limo — a widely used gateway for ENS — rerouting its nameservers and putting nearly 2 million .eth domains at risk. The attacker gained access via EasyDNS account recovery, but DNSSEC validation blocked rogue records because the gateway’s signing keys remained secure. Eth.limo’s team regained control, reported no user losses, and plans to migrate the service to Domainsure to remove account-recovery vectors. The incident underscores operational centralization risks in the Ethereum naming and DeFi access stack, but immediate market impact was limited due to DNSSEC protection and a swift response. Expect renewed attention on DNS security and potential short-term cautious sentiment among Ethereum users and DeFi operators.