{"investigation":{"slug":"velodrome","entity_name":"Velodrome","trust_score":42,"severity_base":null,"score_modifier":0,"confidence":0.72,"status":"draft","content_type":"investigation","summary":"Velodrome is a decentralized exchange and liquidity hub built on the Optimism network, using a ve(3,3) governance and emissions model derived from Andre Cronje's Solidly design. The protocol's core smart contracts have undergone multiple third-party audits and have not been directly exploited, but Velodrome and its sister protocol Aerodrome (both developed by Dromos Labs) have a recurring history of front-end and domain-level compromises — including a 2022 insider theft by a team member, DNS hijacks in 2023, and a 2025 registrar insider-threat incident — plus an active landscape of impersonation and wallet-drainer phishing sites.","sections":[{"content":"Velodrome Finance is a decentralized exchange (DEX) and liquidity marketplace built natively for the Optimism layer-2 network, launched in 2022. It uses a ve(3,3) tokenomics model — an evolution of the 'Solidly' design associated with developer Andre Cronje — in which liquidity providers and protocols lock the VELO token into non-transferable veVELO NFTs to gain voting power over weekly emissions, aligning liquidity incentives across the ecosystem. Velodrome has functioned as the primary liquidity hub for the Optimism Collective and has at various points ranked as the largest DEX on that network by total value locked (TVL), reported at roughly $142 million in late 2024. Velodrome's developer, veDAO/Dromos Labs, separately built Aerodrome Finance on the Base network using the same architecture; the two protocols share code, infrastructure, and in November 2025 announced plans to merge into a single unified protocol and token called 'Aero,' targeted for launch in 2026. The identity of Velodrome's core team has historically not been fully disclosed on official channels, though a co-founder, Alex Cutler, has been publicly identified and quoted in press coverage.","heading":"Protocol Overview","sources":[{"url":"https://www.okx.com/en-us/learn/what-is-velodrome-velo","name":"OKX — What is Velodrome Finance and How Does It Work","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/dromos-labs-merges-aerodrome-and-velodrome-into-new-dex-aero","name":"Dromos Labs merges Aerodrome and Velodrome into new DEX Aero — The Defiant","type":"news_article","credibility":2},{"url":"https://news.bitcoin.com/dromos-labs-reveals-aero-after-merging-2-major-l2-dexs/","name":"Dromos Labs Reveals Aero After Merging 2 Major L2 DEXs — Bitcoin.com News","type":"news_article","credibility":2}],"severity":"low"},{"content":"In August 2022, Velodrome disclosed that approximately $350,000 was misappropriated from a team-controlled operational wallet — used to cover expenses including salaries — before the funds could be swept into the project's treasury multisig. An internal investigation identified the person responsible as a team member operating under the pseudonym 'Gabagool,' who allegedly converted the funds to ETH and routed them through Tornado Cash, a mixing service, reportedly in an attempt to recoup personal losses from the 2022 crypto market downturn. Following community pressure, the funds were returned and Velodrome announced on August 4, 2022 that the $350,000 had been recovered; the team stated it had cut ties with the individual and was engaging legal counsel. In May 2025, this individual — using the pseudonym 'proxystudio.eth' — was publicly identified as a developer for Clanker, an AI-agent token launchpad on Base, after Velodrome co-founder Alex Cutler recognized him at an industry event. Clanker's team announced it was parting ways with him immediately following the disclosure; reporting found no evidence of misconduct during his tenure at Clanker. The affair illustrates a recurring insider-risk theme for the Velodrome/Dromos organization, distinct from the smart-contract or DNS incidents described elsewhere in this report.","heading":"Insider Theft by Team Member 'Gabagool' (August 2022)","sources":[{"url":"https://blockworks.com/news/crypto-marketplace-alleges-350k-stolen-by-insider-gabagool","name":"Crypto Marketplace Alleges $350K Stolen by Insider 'Gabagool' — Blockworks","type":"news_article","credibility":2},{"url":"https://www.cryptotimes.io/2022/08/15/velodrome-regains-350k-stolen-by-its-developer-gabagool/","name":"Velodrome Regains $350k Stolen by its Developer Gabagool — The Crypto Times","type":"news_article","credibility":2},{"url":"https://thedefiant.io/news/defi/clanker-employee-outed-as-velodrome-thief","name":"Clanker Employee Outed as Velodrome Thief — The Defiant","type":"news_article","credibility":2},{"url":"https://www.chaincatcher.com/en/article/2180069","name":"The Clanker team announced a separation from Gabagool — ChainCatcher","type":"news_article","credibility":2}],"severity":"high"},{"content":"On November 29, 2023, Velodrome warned users that 'our frontend is currently compromised' after attackers gained control of its domain through what the team and outside researchers described as a social-engineering attack on its domain registrar, later reported to be Porkbun. The attackers bypassed two-factor authentication on the registrar account, altered nameservers, and redirected velodrome.finance traffic to a phishing clone designed to harvest wallet approvals. Days later, on December 2, 2023, sister protocol Aerodrome (also built by the Velodrome/Dromos team) suffered a materially identical attack via the same registrar, leading commentators to describe it as 'dual frontend hacks in three days.' Blockchain investigator ZachXBT traced stolen funds to specific attacker-controlled addresses and estimated losses in the tens of thousands of dollars from the Velodrome leg of the attack, with combined estimates across both platforms ranging from roughly $100,000 to $250,000 depending on the source and measurement window. Both protocols stated their underlying smart contracts and treasury funds were not affected — the compromise was confined to the web front end — and published a joint incident report on December 3, 2023, subsequently launching a bounty program with Arkham Intelligence to help identify the attackers. Velodrome urged users to rely on decentralized/IPFS-hosted frontend mirrors rather than the primary domain during the incident.","heading":"DNS / Frontend Compromise — November–December 2023","sources":[{"url":"https://www.theblock.co/post/265104/velodrome-aerodrome-hit-by-attack-on-front-end-websites","name":"Velodrome, Aerodrome hit by attack on front-end websites — The Block","type":"news_article","credibility":1},{"url":"https://www.theblock.co/post/265776/velodrome-aerodrome-websites-compromised-for-second-time-in-days","name":"Velodrome, Aerodrome websites compromised for second time in days — The Block","type":"news_article","credibility":1},{"url":"https://dailycoin.com/velodrome-and-aerodrome-suffer-dual-frontend-hacks-in-3-days/","name":"Velodrome and Aerodrome Suffer Dual Frontend Hacks in 3 Days — DailyCoin","type":"news_article","credibility":2},{"url":"https://beincrypto.com/velodrome-aerodrome-front-end-exploit/","name":"Velodrome and Aerodrome: Front-End Exploit Leads to Losses — BeInCrypto","type":"news_article","credibility":2},{"url":"https://domainsure.com/news/case-study-lessons-on-enhancing-cybersecurity-from-velodromes-dns-attack/","name":"Case Study: Lessons on Enhancing Cybersecurity from Velodrome's DNS Attack — DomainSure","type":"research","credibility":2}],"severity":"high"},{"content":"On November 22, 2025, Velodrome and Aerodrome suffered a second, larger-scale DNS hijacking incident. Attackers gained control of domains registered through NameSilo (with Aerodrome's .box and .finance domains managed via Box Domains/My.box) and were able to disable DNSSEC and bypass multisig-based DNS controls in the 3DNS system, redirecting the protocols' primary web domains to malicious clones. According to the teams' own incident disclosure, root cause was traced to an insider compromise at registrar NameSilo rather than a technical flaw in the protocols' own infrastructure. Victims who interacted with the fraudulent site were induced to sign malicious approval transactions; reported losses range from approximately $700,000 (per the protocols' own incident report) to over $1 million (per independent on-chain analysts) drained from user wallets within roughly one hour before the attack was contained. The teams stated their on-chain smart contracts and treasury funds were unaffected. Response measures reported by the teams and by security firm Halborn included rapid wallet-provider phishing warnings (e.g., from MetaMask and Coinbase Wallet) within minutes, containment assistance from security partners including Blockaid, SEAL, and FTI Consulting, migration of users to ENS-based decentralized mirrors (e.g., aero-drome.eth.limo) instead of traditional DNS, and an announced compensation/grant program for affected users. The incident occurred while Dromos Labs was finalizing the announced Aerodrome–Velodrome merger into 'Aero'; reporting found no evidence connecting the DNS attack to the merger process itself.","heading":"DNS / Frontend Compromise — November 2025 (NameSilo Insider Threat)","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-aerodrome-finance-hack-november-2025","name":"Explained: The Aerodrome Finance Hack (November 2025) — Halborn","type":"research","credibility":2},{"url":"https://www.theblock.co/post/380037/top-dexs-aerodrome-velodrome-hit-with-front-end-compromise-urge-users-to-avoid-main-domains","name":"Top DEXs Aerodrome, Velodrome hit with front-end compromise — The Block","type":"news_article","credibility":1},{"url":"https://www.coindesk.com/web3/2025/11/22/aerodrome-finance-hit-by-front-end-attack-users-urged-to-avoid-main-domain","name":"Aerodrome Finance Hit by Front-End Attack — CoinDesk","type":"news_article","credibility":1},{"url":"https://incrypted.com/en/aerodrome-and-velodrome-published-report-on-namesilo-hack/","name":"Aerodrome and Velodrome Published Report on NameSilo Hack — Incrypted","type":"news_article","credibility":2},{"url":"https://news.bitcoin.com/dns-attack-strikes-aerodrome-and-velodrome-as-aero-merger-nears/","name":"DNS Attack Strikes Aerodrome and Velodrome as Aero Merger Nears — Bitcoin.com News","type":"news_article","credibility":2},{"url":"https://www.web3isgoinggreat.com/?id=aerodrome-and-velodrome-website-takeovers","name":"Aerodrome and Velodrome suffer website takeovers, again — Web3 Is Going Great","type":"community_report","credibility":2}],"severity":"critical"},{"content":"In connection with the November 2023 DNS hijack, blockchain investigator ZachXBT publicly identified on-chain addresses to which stolen funds were traced, including wallets reported as 0x02BA13f39D7df9C3F7592257b636eD6C7CC4ae78 and 0xf64fCEdFCe714Bbe835761e54D7067f2f8231443 (addresses as reported in secondary coverage; character-level accuracy should be verified against ZachXBT's original social media posts before operational use, as these summaries were not independently cross-checked against a primary on-chain source in this investigation). Reporting indicated stolen funds — on the order of $40,000 tied specifically to Velodrome's leg of the attack, per The Block's on-chain review — were split across multiple addresses with a portion ultimately deposited to the KuCoin exchange. This claim rests on Tier 2 secondary reporting of a Tier 3 social-media analysis (ZachXBT's posts) and should be treated as a lead for further on-chain verification rather than a fully confirmed attribution.","heading":"On-Chain Attacker Addresses (2023 Incident)","sources":[{"url":"https://www.theblock.co/post/265104/velodrome-aerodrome-hit-by-attack-on-front-end-websites","name":"Velodrome, Aerodrome hit by attack on front-end websites — The Block","type":"news_article","credibility":1},{"url":"https://github.com/liqtags/crypto-rekts/blob/main/rekts/Velodrome-Finance-Exploit.md","name":"Velodrome-Finance-Exploit.md — crypto-rekts (community incident archive)","type":"community_report","credibility":3}],"severity":"medium"},{"content":"Velodrome's core smart contracts have been subject to multiple independent third-party audits, and no direct exploit of the deployed contract logic (as opposed to front-end/DNS infrastructure) has been publicly reported to date. A May 2022 Code4rena competitive audit covering 17 contracts and roughly 3,443 lines of Solidity identified six high-severity issues prior to mainnet launch, including a vote-accumulation flaw via NFT mint/burn cycling, logic errors blocking approved (non-owner) operators from merge/withdraw actions, incorrect reset of reward-eligibility flags after balance-changing actions, a first-epoch bribe-lockup bug, a vote-timing exploit allowing incentive-mechanism bypass, and insufficient error handling in LayerZero cross-chain messaging that could permanently block bridge communication; these were competition findings intended for remediation before or shortly after launch rather than confirmed live exploits. Velodrome's protocol documentation states the project has also engaged security firm Spearbit for reviews in 2023, and a later audit by ChainSecurity covering Velodrome's Superchain interoperability expansion (multi-chain state consistency and Hyperlane bridge integration) found the reviewed codebase to provide 'a high level of security' after initial issues — including a voting-period bypass and bridge metadata misuse — were identified and corrected during the engagement; the report also flagged a residual assumption in a later code version that cross-chain messages process within a one-hour window, absent which temporary voting-power inflation could occur. As with any time-boxed audit, these reviews do not guarantee the absence of undiscovered vulnerabilities.","heading":"Smart Contract Security and Audits","sources":[{"url":"https://code4rena.com/reports/2022-05-velodrome","name":"Code4rena Velodrome Finance Audit Report (2022-05)","type":"research","credibility":2},{"url":"https://www.chainsecurity.com/security-audit/velodrome-superchain-interoperability","name":"Velodrome Superchain Interoperability Audit — ChainSecurity","type":"research","credibility":2},{"url":"https://docs.velodrome.finance/security","name":"Velodrome Finance Security Documentation","type":"official","credibility":2}],"severity":"medium"},{"content":"Velodrome (and its Dromos Labs sibling Aerodrome) has now experienced at least three publicly reported DNS/registrar-level or domain-management compromises across November–December 2023 and November 2025, despite the underlying smart contracts remaining unaffected in each case. Security researchers and industry commentary (including Halborn and DomainSure) have characterized this as a structural risk pattern common to DeFi front ends generally: because most users interact with protocols through a centrally-registered Web2 domain rather than directly with audited on-chain contracts, a single social-engineering or insider compromise at a domain registrar can be used to harvest wallet approvals from a large user base within a short window, regardless of how secure the underlying contract code is. Commentary following the 2025 incident noted the recurrence — the same class of attack succeeding against the same two protocols roughly two years apart — as evidence that mitigations adopted after 2023 (moving users toward IPFS/decentralized frontend mirrors) were not sufficient on their own, prompting the teams' subsequent move toward ENS-based mirror domains as a longer-term fix. This is best understood as an ongoing, unresolved category of risk for the protocol rather than a single closed incident.","heading":"Persistent Frontend / Web2 Attack Surface Risk","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-aerodrome-finance-hack-november-2025","name":"Explained: The Aerodrome Finance Hack (November 2025) — Halborn","type":"research","credibility":2},{"url":"https://domainsure.com/news/case-study-lessons-on-enhancing-cybersecurity-from-velodromes-dns-attack/","name":"Case Study: Lessons on Enhancing Cybersecurity from Velodrome's DNS Attack — DomainSure","type":"research","credibility":2},{"url":"https://www.web3isgoinggreat.com/?id=aerodrome-and-velodrome-website-takeovers","name":"Aerodrome and Velodrome suffer website takeovers, again — Web3 Is Going Great","type":"community_report","credibility":2},{"url":"https://financefeeds.com/base-and-optimisms-top-dexs-suffer-dns-hijack-in-repeat-attack-nearly-two-years-later/","name":"Base and Optimism's Top DEXs Suffer DNS Hijack in Repeat Attack Nearly Two Years Later — FinanceFeeds","type":"news_article","credibility":2}],"severity":"high"},{"content":"Independent of the direct DNS compromises of Velodrome's own domains, there is an ongoing pattern of unrelated third-party impersonation sites that clone Velodrome's branding to run wallet-drainer scams unconnected to any breach of the real protocol. Security researchers documented a fraudulent site at a lookalike domain (reported as governance-velo[.]finance) that mimicked Velodrome's interface and falsely promised early token rewards to users who 'voted' within 24 hours; connecting a wallet to the site triggered a request for a broad token-spending approval which, once granted, allowed the scam operators to drain approved tokens via standard ERC-20 transferFrom calls rather than by stealing private keys directly. Reports on this specific scam site were published in October 2025, and researchers noted that operators of this style of scam typically rotate through many domains in parallel, making takedown efforts difficult to keep pace with. These campaigns are not evidence of any compromise of Velodrome's legitimate infrastructure, but reflect the broader risk that the protocol's brand and governance/voting model are attractive templates for unaffiliated phishing operations.","heading":"Impersonation Scams and Phishing Sites","sources":[{"url":"https://malwaretips.com/blogs/beware-the-fake-velodrome-velo-vote-rewards-scam-sites/","name":"Beware the Fake Velodrome VELO Vote Rewards Scam Sites — MalwareTips","type":"community_report","credibility":2},{"url":"https://www.pcrisk.com/removal-guides/34016-velodrome-finance-velo-vote-rewards-scam","name":"Velodrome Finance VELO Vote Rewards Scam — PCrisk","type":"community_report","credibility":2}],"severity":"medium"},{"content":"Velodrome's core development team has historically maintained significant pseudonymity, with the protocol's official channels not fully disclosing team members' identities, though co-founder Alex Cutler has been named and quoted in mainstream and crypto-industry press. The team's original mandate traces to the veDAO initiative, which engaged with Andre Cronje's Solidly ecosystem on Fantom before the team built Velodrome's independent ve(3,3) implementation on Optimism. This partial anonymity is a governance-transparency consideration common across many DeFi protocols rather than unique misconduct, but it is relevant context alongside the 2022 Gabagool insider-theft incident, in which the perpetrator was an unnamed, pseudonymous team member operating with significant access to operational funds — an arrangement that a fully identified, accountable team structure might have made more difficult to exploit or easier to resolve quickly. Velodrome's TVL and fee generation have at times been significant relative to the Optimism ecosystem (reported as the top Optimism-native DEX by TVL in 2024), and the protocol is now positioned to merge with Aerodrome into a jointly governed 'Aero' protocol expected in 2026, which will consolidate governance and treasury functions across both prior communities.","heading":"Team Background and Governance","sources":[{"url":"https://blockworks.com/news/crypto-marketplace-alleges-350k-stolen-by-insider-gabagool","name":"Crypto Marketplace Alleges $350K Stolen by Insider 'Gabagool' — Blockworks","type":"news_article","credibility":2},{"url":"https://thedefiant.io/news/defi/clanker-employee-outed-as-velodrome-thief","name":"Clanker Employee Outed as Velodrome Thief — The Defiant","type":"news_article","credibility":2},{"url":"https://thedefiant.io/news/defi/dromos-labs-merges-aerodrome-and-velodrome-into-new-dex-aero","name":"Dromos Labs merges Aerodrome and Velodrome into new DEX Aero — The Defiant","type":"news_article","credibility":2}],"severity":"medium"}],"timeline":[{"date":"2022","event":"Velodrome Finance launches as a native decentralized exchange on the Optimism network, using a ve(3,3) governance and emissions model.","source":"OKX — What is Velodrome Finance","source_url":"https://www.okx.com/en-us/learn/what-is-velodrome-velo"},{"date":"2022-08-04","event":"Velodrome announces recovery of roughly $350,000 stolen from a team-controlled wallet by a team member operating under the pseudonym 'Gabagool'.","source":"The Crypto Times","source_url":"https://www.cryptotimes.io/2022/08/15/velodrome-regains-350k-stolen-by-its-developer-gabagool/","date_evidence":"On August 04, the trading and liquidity platform Velodrome Finance recovered $350k stolen in a hack from a team member."},{"date":"2023-11","event":"Velodrome discloses that its frontend has been compromised via a DNS hijack targeting its domain registrar.","source":"The Block","source_url":"https://www.theblock.co/post/265104/velodrome-aerodrome-hit-by-attack-on-front-end-websites","date_evidence":"on November 29\" when the platform revealed a DNS attack targeting their official website","date_original":"2023-11-29"},{"date":"2023-12","event":"Sister protocol Aerodrome suffers a similar DNS hijack attack days after Velodrome's incident.","source":"The Block","source_url":"https://www.theblock.co/post/265776/velodrome-aerodrome-websites-compromised-for-second-time-in-days","date_evidence":"on December 2\" Aerodrome independently reported its own DNS attack incident","date_original":"2023-12-02"},{"date":"2023-12","event":"Velodrome and Aerodrome publish a joint incident report on the November-December 2023 DNS attacks.","source":"Incrypted","source_url":"https://incrypted.com/en/aerodrome-and-velodrome-published-report-on-namesilo-hack/","date_evidence":"Both protocols published detailed findings in their incident report","date_original":"2023-12-03"},{"date":"2024","event":"Velodrome reported as the largest Optimism-native DEX by total value locked, at approximately $142 million.","source":"OKX — What is Velodrome Finance","source_url":"https://www.okx.com/en-us/learn/what-is-velodrome-velo"},{"date":"2024-11","event":"Clanker, an AI-agent token launchpad on Base, launches with a developer later identified as the pseudonymous 2022 Velodrome insider 'Gabagool' (operating as 'proxystudio.eth') on its team.","source":"The Defiant","source_url":"https://thedefiant.io/news/defi/clanker-employee-outed-as-velodrome-thief"},{"date":"2025-05","event":"Clanker developer 'proxystudio.eth' is publicly identified as the 2022 Velodrome insider-theft perpetrator 'Gabagool' after being recognized by Velodrome co-founder Alex Cutler; Clanker announces the two have parted ways.","source":"ChainCatcher","source_url":"https://www.chaincatcher.com/en/article/2180069"},{"date":"2025-10","event":"Security researchers publish warnings about a fake 'Velodrome VELO Vote Rewards' phishing site using a wallet-drainer contract, unrelated to any breach of Velodrome's real infrastructure.","source":"PCrisk","source_url":"https://www.pcrisk.com/removal-guides/34016-velodrome-finance-velo-vote-rewards-scam"},{"date":"2025-11-22","event":"Velodrome and Aerodrome suffer a second, larger DNS hijacking attack traced to an insider compromise at registrar NameSilo, resulting in reported losses of roughly $700,000 to over $1 million from users who interacted with the fraudulent front end.","source":"The Block","source_url":"https://www.theblock.co/post/380037/top-dexs-aerodrome-velodrome-hit-with-front-end-compromise-urge-users-to-avoid-main-domains","date_evidence":"Publication Date: November 22, 2025"},{"date":"2025-11","event":"Dromos Labs announces plans to merge Aerodrome and Velodrome into a single unified protocol and token, 'Aero,' expanding to Ethereum and Circle's Arc chain, with launch targeted for 2026.","source":"The Defiant","source_url":"https://thedefiant.io/news/defi/dromos-labs-merges-aerodrome-and-velodrome-into-new-dex-aero"}],"sources_used":[{"url":"https://www.okx.com/en-us/learn/what-is-velodrome-velo","name":"OKX — What is Velodrome Finance and How Does It Work","type":"other","archive_url":"https://web.archive.org/web/20260829203430/https://www.okx.com/en-us/learn/what-is-velodrome-velo","credibility":3,"archive_timestamp":"2026-08-29T20:34:30+00:00"},{"url":"https://blockworks.com/news/crypto-marketplace-alleges-350k-stolen-by-insider-gabagool","name":"Crypto Marketplace Alleges $350K Stolen by Insider 'Gabagool' — Blockworks","type":"news_article","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.cryptotimes.io/2022/08/15/velodrome-regains-350k-stolen-by-its-developer-gabagool/","name":"Velodrome Regains $350k Stolen by its Developer Gabagool — The Crypto Times","type":"news_article","archive_url":"https://web.archive.org/web/20260829201714/https://www.cryptotimes.io/2022/08/15/velodrome-regains-350k-stolen-by-its-developer-gabagool/","credibility":2,"archive_timestamp":"2026-08-29T20:17:14+00:00"},{"url":"https://thedefiant.io/news/defi/clanker-employee-outed-as-velodrome-thief","name":"Clanker Employee Outed as Velodrome Thief — The Defiant","type":"news_article","archive_url":"http://web.archive.org/web/20260201212908/https://thedefiant.io/news/defi/clanker-employee-outed-as-velodrome-thief","credibility":2,"archive_timestamp":"2026-02-01T21:29:08+00:00"},{"url":"https://www.chaincatcher.com/en/article/2180069","name":"The Clanker team announced a separation from Gabagool — ChainCatcher","type":"news_article","archive_url":"https://web.archive.org/web/20260829201320/https://www.chaincatcher.com/en/article/2180069","credibility":2,"archive_timestamp":"2026-08-29T20:13:20+00:00"},{"url":"https://www.theblock.co/post/265104/velodrome-aerodrome-hit-by-attack-on-front-end-websites","name":"Velodrome, Aerodrome hit by attack on front-end websites — The Block","type":"news_article","archive_url":null,"credibility":1,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.theblock.co/post/265776/velodrome-aerodrome-websites-compromised-for-second-time-in-days","name":"Velodrome, Aerodrome websites compromised for second time in days — The Block","type":"news_article","archive_url":"http://web.archive.org/web/20251128002704/https://www.theblock.co/post/265776/velodrome-aerodrome-websites-compromised-for-second-time-in-days","credibility":1,"archive_timestamp":"2025-11-28T00:27:04+00:00"},{"url":"https://dailycoin.com/velodrome-and-aerodrome-suffer-dual-frontend-hacks-in-3-days/","name":"Velodrome and Aerodrome Suffer Dual Frontend Hacks in 3 Days — DailyCoin","type":"news_article","archive_url":"https://web.archive.org/web/20260830084825/https://dailycoin.com/velodrome-and-aerodrome-suffer-dual-frontend-hacks-in-3-days/","credibility":2,"archive_timestamp":"2026-08-30T08:48:25+00:00"},{"url":"https://beincrypto.com/velodrome-aerodrome-front-end-exploit/","name":"Velodrome and Aerodrome: Front-End Exploit Leads to Losses — BeInCrypto","type":"news_article","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://domainsure.com/news/case-study-lessons-on-enhancing-cybersecurity-from-velodromes-dns-attack/","name":"Case Study: Lessons on Enhancing Cybersecurity from Velodrome's DNS Attack — DomainSure","type":"research","archive_url":"http://web.archive.org/web/20260612013414/https://domainsure.com/news/case-study-lessons-on-enhancing-cybersecurity-from-velodromes-dns-attack/","credibility":2,"archive_timestamp":"2026-06-12T01:34:14+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-aerodrome-finance-hack-november-2025","name":"Explained: The Aerodrome Finance Hack (November 2025) — Halborn","type":"research","archive_url":"http://web.archive.org/web/20260414120419/https://www.halborn.com/blog/post/explained-the-aerodrome-finance-hack-november-2025","credibility":2,"archive_timestamp":"2026-04-14T12:04:19+00:00"},{"url":"https://www.theblock.co/post/380037/top-dexs-aerodrome-velodrome-hit-with-front-end-compromise-urge-users-to-avoid-main-domains","name":"Top DEXs Aerodrome, Velodrome hit with front-end compromise — The Block","type":"news_article","archive_url":"http://web.archive.org/web/20260418124116/https://www.theblock.co/post/380037/top-dexs-aerodrome-velodrome-hit-with-front-end-compromise-urge-users-to-avoid-main-domains","credibility":1,"archive_timestamp":"2026-04-18T12:41:16+00:00"},{"url":"https://www.coindesk.com/web3/2025/11/22/aerodrome-finance-hit-by-front-end-attack-users-urged-to-avoid-main-domain","name":"Aerodrome Finance Hit by Front-End Attack — CoinDesk","type":"news_article","archive_url":"http://web.archive.org/web/20260103063732/https://www.coindesk.com/web3/2025/11/22/aerodrome-finance-hit-by-front-end-attack-users-urged-to-avoid-main-domain","credibility":1,"archive_timestamp":"2026-01-03T06:37:32+00:00"},{"url":"https://incrypted.com/en/aerodrome-and-velodrome-published-report-on-namesilo-hack/","name":"Aerodrome and Velodrome Published Report on NameSilo Hack — Incrypted","type":"news_article","archive_url":"http://web.archive.org/web/20251124123834/https://incrypted.com/en/aerodrome-and-velodrome-published-report-on-namesilo-hack/","credibility":2,"archive_timestamp":"2025-11-24T12:38:34+00:00"},{"url":"https://news.bitcoin.com/dns-attack-strikes-aerodrome-and-velodrome-as-aero-merger-nears/","name":"DNS Attack Strikes Aerodrome and Velodrome as Aero Merger Nears — Bitcoin.com News","type":"news_article","archive_url":"http://web.archive.org/web/20251229144420/https://news.bitcoin.com/dns-attack-strikes-aerodrome-and-velodrome-as-aero-merger-nears/","credibility":2,"archive_timestamp":"2025-12-29T14:44:20+00:00"},{"url":"https://www.web3isgoinggreat.com/?id=aerodrome-and-velodrome-website-takeovers","name":"Aerodrome and Velodrome suffer website takeovers, again — Web3 Is Going Great","type":"community_report","archive_url":"http://web.archive.org/web/20260307053549/https://www.web3isgoinggreat.com/?id=aerodrome-and-velodrome-website-takeovers","credibility":2,"archive_timestamp":"2026-03-07T05:35:49+00:00"},{"url":"https://github.com/liqtags/crypto-rekts/blob/main/rekts/Velodrome-Finance-Exploit.md","name":"Velodrome-Finance-Exploit.md — crypto-rekts (community incident archive)","type":"community_report","archive_url":"https://web.archive.org/web/20260829193126/https://github.com/liqtags/crypto-rekts/blob/main/rekts/Velodrome-Finance-Exploit.md","credibility":3,"archive_timestamp":"2026-08-29T19:31:26+00:00"},{"url":"https://code4rena.com/reports/2022-05-velodrome","name":"Code4rena Velodrome Finance Audit Report (2022-05)","type":"research","archive_url":"http://web.archive.org/web/20260606110058/https://code4rena.com/reports/2022-05-velodrome","credibility":2,"archive_timestamp":"2026-06-06T11:00:58+00:00"},{"url":"https://www.chainsecurity.com/security-audit/velodrome-superchain-interoperability","name":"Velodrome Superchain Interoperability Audit — ChainSecurity","type":"research","archive_url":"http://web.archive.org/web/20260315015903/https://www.chainsecurity.com/security-audit/velodrome-superchain-interoperability","credibility":2,"archive_timestamp":"2026-03-15T01:59:03+00:00"},{"url":"https://docs.velodrome.finance/security","name":"Velodrome Finance Security Documentation","type":"official","archive_url":null,"credibility":2,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://financefeeds.com/base-and-optimisms-top-dexs-suffer-dns-hijack-in-repeat-attack-nearly-two-years-later/","name":"Base and Optimism's Top DEXs Suffer DNS Hijack in Repeat Attack Nearly Two Years Later — FinanceFeeds","type":"news_article","archive_url":"https://web.archive.org/web/20260830085441/https://financefeeds.com/base-and-optimisms-top-dexs-suffer-dns-hijack-in-repeat-attack-nearly-two-years-later/","credibility":2,"archive_timestamp":"2026-08-30T08:54:41+00:00"},{"url":"https://malwaretips.com/blogs/beware-the-fake-velodrome-velo-vote-rewards-scam-sites/","name":"Beware the Fake Velodrome VELO Vote Rewards Scam Sites — MalwareTips","type":"community_report","archive_url":"http://web.archive.org/web/20251013015806/https://malwaretips.com/blogs/beware-the-fake-velodrome-velo-vote-rewards-scam-sites/","credibility":2,"archive_timestamp":"2025-10-13T01:58:06+00:00"},{"url":"https://www.pcrisk.com/removal-guides/34016-velodrome-finance-velo-vote-rewards-scam","name":"Velodrome Finance VELO Vote Rewards Scam — PCrisk","type":"community_report","archive_url":"http://web.archive.org/web/20260510201852/https://www.pcrisk.com/removal-guides/34016-velodrome-finance-velo-vote-rewards-scam","credibility":2,"archive_timestamp":"2026-05-10T20:18:52+00:00"},{"url":"https://thedefiant.io/news/defi/dromos-labs-merges-aerodrome-and-velodrome-into-new-dex-aero","name":"Dromos Labs merges Aerodrome and Velodrome into new DEX Aero — The Defiant","type":"news_article","archive_url":"http://web.archive.org/web/20260311031457/https://thedefiant.io/news/defi/dromos-labs-merges-aerodrome-and-velodrome-into-new-dex-aero","credibility":2,"archive_timestamp":"2026-03-11T03:14:57+00:00"},{"url":"https://news.bitcoin.com/dromos-labs-reveals-aero-after-merging-2-major-l2-dexs/","name":"Dromos Labs Reveals Aero After Merging 2 Major L2 DEXs — Bitcoin.com News","type":"news_article","archive_url":"http://web.archive.org/web/20260715194931/https://news.bitcoin.com/dromos-labs-reveals-aero-after-merging-2-major-l2-dexs/","credibility":2,"archive_timestamp":"2026-07-15T19:49:31+00:00"}],"source_tags":["zachxbt"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-code-investigator","created_at":"2026-05-04T16:05:03.856649+00:00","updated_at":"2026-08-30T16:47:13.803739+00:00"}}