/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← β†’ days Β· ↑ ↓ browse Β· Enter similar Β· o open

Researchers: hackers have exploited a Squarespace flaw to hijack domains, apparently mostly from crypto businesses, that were migrated from Google Domains

β€œIf you bought Google Workspace via Google Domains, Squarespace is now your authorized reseller,” the help document explains. … BrianKrebs / @briankrebs@infosec.exchange : At least a dozen organizations with domain names at domain registrar Squarespace saw their websites hijacked last week.Β  Squarespace bought all assets of Google Domains a year ago, but many customers still haven't set up their new accounts. … X: @celernetwork : βœ…Thanks to our 24/7 domain security monitoring, an attempted takeover of Celer domains was successfully intercepted. All DNS records have been recovered. Our ongoing investigation indicates that the attack vector likely involved third parties beyond our control. πŸ‘οΈThe Celer Pendle / @pendle_fi : Post Mortem For context - Squarespace purchased all domain registrations and related customer accounts from Google Domains in June 2023, which forced the migration of domains. Recently, attackers exploited a vulnerability in Squarespace, hijacking domains hosted on their @compoundfinance : βœ… Update: Thanks to the tenacious efforts of so many in the community, the https://compound.finance/ website is once again secure. Please always remain vigilant in clicking links to avoid phishing scams. Make sure to restart your browser to ensure visiting the proper website. If @samczsun : multiple crypto projects have had their domains mysteriously hijacked from their @squarespace account. consider transferring your domain to one of these instead: - @Cloudflare - @awscloud Route53 - @markmonitor - @CSCDBS @wordpressdotcom : If you don't like where your domains ended up (𝘀𝘰𝘢𝘨𝘩 Squarespace 𝘀𝘰𝘢𝘨𝘩), move to a safer option with us at https://wordpress.com/. Visit https://wordpress.com/... and let us get you started ASAP. Forums: Hacker News : Researchers: Weak Security Defaults Enabled Squarespace Domains Hijacks

Krebs on Security Brian Krebs

Context & Ripple Effects

Squarespace’s acquisition and migration of Google Domains registrations left some customers without fully configured new accounts, creating a transition point that attackers appear to have exploited. The incidents center on control of DNS and domain accounts, rather than a compromise of the affected businesses’ own web infrastructure.

Registrar-level account and DNS changes have repeatedly been a high-impact attack path: a prior GoDaddy social-engineering incident changed DNS records at crypto platforms, while a registrar-linked hijack affected major domains years earlier. This case puts the risk at the intersection of a large account migration and incomplete customer setup.

First-order effects

  • Affected Squarespace customersβ€”apparently concentrated among crypto businessesβ€”can lose control of their domains and DNS records, exposing visitors to attacker-controlled destinations until records are restored.
  • Squarespace must address the exploited weakness and help migrated Google Domains customers complete or secure account setup; security monitoring teams become an immediate backstop for detecting takeover attempts.

Second-order effects

  • Crypto projects and other high-value domain holders are likely to scrutinize registrar access, DNS-change alerts, and recovery procedures, because a domain takeover can disrupt the public-facing trust channel even when core systems remain intact.
  • The incident raises the operational cost of registrar migrations: providers must make account activation and ownership verification resilient enough that uncompleted transitions do not become an attack surface.

Third-order effects

  • If similar incidents persist, domain registrars will increasingly compete on transition security and recovery controls, not just registration and hosting featuresβ€”an example of domain abuse extending beyond newly registered lookalikes to control of legitimate domains.
  • The broader structural risk is that consolidation and migration concentrate domain-control failures at a few platforms; stronger default safeguards may become necessary, though this report alone does not establish how widespread the underlying flaw is.

The trend: Domain management is becoming a more visible layer of platform security, with account migrations and DNS control emerging as critical trust dependencies.

Discussion

  • @celernetwork @celernetwork on x
    βœ…Thanks to our 24/7 domain security monitoring, an attempted takeover of Celer domains was successfully intercepted. All DNS records have been recovered. Our ongoing investigation indicates that the attack vector likely involved third parties beyond our control. πŸ‘οΈThe Celer
  • @pendle_fi Pendle on x
    Post Mortem For context - Squarespace purchased all domain registrations and related customer accounts from Google Domains in June 2023, which forced the migration of domains. Recently, attackers exploited a vulnerability in Squarespace, hijacking domains hosted on their
  • @samczsun @samczsun on x
    multiple crypto projects have had their domains mysteriously hijacked from their @squarespace account. consider transferring your domain to one of these instead: - @Cloudflare - @awscloud Route53 - @markmonitor - @CSCDBS
  • @compoundfinance @compoundfinance on x
    βœ… Update: Thanks to the tenacious efforts of so many in the community, the https://compound.finance/ website is once again secure. Please always remain vigilant in clicking links to avoid phishing scams. Make sure to restart your browser to ensure visiting the proper website. If