Preview surface — demo data. Where real data exists today (e.g. RealT, BlackRock BUIDL, Lift Dollar) we render it; everywhere else we render synthetic enrichment generated deterministically from public signal and clearly marked Demo or Inferred. The Phase 3 roadmap replaces every synthetic source with live ingestion — see Methodology → Exposure Graph & Similarity Engine.
← back to incident ledger

frontend dns hijackDemo

Jan 25, 2025 · $10.4M · frontend

Narrative

On 2025-01-25, Bridge.xyz / Stripe suffered a frontend dns hijack incident resulting in approximately $10,361,159 in losses. The exploit targeted the frontend layer. Attribution: unattributed_criminal. This is a demonstration entry — not a real incident.

Classification

Root cause
frontend_dns_hijack
Secondary causes
Attack layer
frontend
Strategy
tech_vuln
Actor role
target
Attribution
unattributed_criminal
Attacker address
Flash loan
no
Audited at time
yes
Bounty at time
no

AADAPT mappings

DEMO:AADAPT.TA0001DEMO:AADAPT.TA0008DEMO:AADAPT.T1071.001DEMO:AADAPT.T1583.001

Evidence

Disclosure date
Jan 28, 2025
Funds recovered
Audit firms at time
Quantstamp, Trail of Bits
Post-mortem URLs (synthetic)
  • https://medium.com/bridge-xyz-stripe/post-mortem-bridge-xyz-stripe-2025-01-25
  • https://rekt.news/bridge-xyz-stripe-rekt
tx hashes (1)
  • 0xed6cec34adc815819b66bfcf870a61ab6ddadd32c79ed85e668547027af1243b