/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

GoDaddy confirms some of its staff fell for a social engineering scam, after hackers changed the email and DNS records for a number of crypto trading platforms

Fraudsters redirected email and web traffic destined for several cryptocurrency trading platforms over the past week.

Krebs on Security Brian Krebs

Context & Ripple Effects

This incident extends a documented pattern rather than arriving cold: a year earlier, Krebs detailed how spam campaigns ran through a previously reported weakness at GoDaddy, and months after that GoDaddy reset passwords on compromised accounts while taking down 15,000+ scam-hosted subdomains. The 2020 episode is different in kind — the target was GoDaddy's own staff, not its customers' accounts.

The method matters: fraudsters didn't breach infrastructure, they talked employees into changing email and DNS records for crypto trading platforms, redirecting traffic they control. That same people-and-process attack surface recurs in the later record — the third-party access to 1.2M Managed WordPress accounts disclosed via SEC filing in 2021, then the multiyear breach with stolen source code and server malware found in late 2022.

First-order effects

  • Customers of the affected crypto trading platforms had their email and web traffic redirected for roughly a week — exposure to intercepted credentials, phishing pages, and fraudulent communications bearing the platforms' own domains.
  • The named platforms must assume attacker-controlled mail flows during the window, forcing credential rotations and incident notifications regardless of whether theft is confirmed.

Second-order effects

  • High-value customers — exchanges and trading platforms chief among them — have a concrete reason to split registrar and DNS providers or demand registrar-lock and out-of-band change verification from GoDaddy specifically.
  • Rival registrars gain a marketing wedge built on GoDaddy's accumulating incident record, competing for exactly the security-sensitive accounts most likely to churn after this disclosure.

Third-order effects

  • Across the 2019 spam weakness, the 2020 social engineering, the 2021 managed-hosting access, and the 2022 multiyear intrusion, the consistent failure point is GoDaddy's internal controls rather than any single exploit — pointing toward concentration risk at dominant registrars being treated as a systemic concern by their largest customers.
  • If DNS control keeps proving sufficient to hijack even sophisticated financial brands, expect multi-provider DNS architectures and stricter change-authorization norms to become baseline practice among high-value domains rather than an edge case.

The trend: Domain registrars are consolidating into a recurring attack surface where social engineering of a single provider's staff can redirect traffic for entire industries, pushing high-value sites toward redundant, verification-hardened DNS setups.

Discussion

  • @woodyatpch Bill Woodcock on x
    I don't know how many times this needs to happen before people understand that registrars will always be the weak point in this chain, and that you can't secure millions or billions of dollars with a $9.95 link in the chain. DNSSEC/DANE in-band validation is necessary. https://tw…
  • @lapierrelafitte Pierre Lafitte on x
    You are never safe. Stay paranoid. https://twitter.com/...
  • @koenrh Koen Rouwhorst on x
    Still relevant: https://blendle.engineering/ ... This attack vector is entirely preventable: 1. Transfer your business-critical domain names to a registrar that has experience protecting high-value domain names (MarkMonitor, CSC, Cloudflare). 2. Ask them to turn on registry locks…
  • @mdudas Mike Dudas on x
    Social engineering attack against @GoDaddy employees impacts crypto platforms @Liquid_Global + @NiceHashMining. Other firms potentially impacted include @Bibox365, @CelsiusNetwork & @wirexapp. https://krebsonsecurity.com/ ...
  • @briankrebs @briankrebs on x
    Exclusive: Fraudsters changed the email and DNS records for a number of cryptocurrency trading platforms this week, after successfully social engineering employees at GoDaddy, the world's largest domain name registrar. https://krebsonsecurity.com/ ... https://twitter.com/...
  • @quinnypig Corey Quinn on x
    No daddy. https://twitter.com/...
  • @stilgherrian @stilgherrian on x
    It's always DNS... https://twitter.com/...
  • @film_girl Christina Warren on x
    Holy shit. Of all the people you don't want social engineered into doing bad stuff it's the people that control access to DNS and domain names! https://twitter.com/...
  • @eastdakota Matthew Prince on x
    Secure your domain registration. Secure your DNS. Don't get those pieces correct and none of your other security will matter. https://twitter.com/...