/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

GoDaddy confirms some of its staff fell for a social engineering scam, after hackers changed the email and DNS records for a number of crypto trading platforms

Fraudsters redirected email and web traffic destined for several cryptocurrency trading platforms over the past week.

Krebs on Security Brian Krebs

Context & Ripple Effects

This is not GoDaddy's first security story, and the pattern is what makes it matter. Researchers had already tied widely received spam campaigns to a previously detailed weakness at GoDaddy.com, and a year later the company reset passwords on hundreds of compromised accounts while taking down more than 15,000 abused subdomains.

First-order effects

  • The immediate victims are the crypto trading platforms whose email and web traffic was silently rerouted once attackers altered their DNS records — customers saw attacker-controlled destinations with no visible warning.
  • GoDaddy's own staff are now the confirmed attack surface: the company says social engineering of employees, not a technical exploit, is what gave hackers the access to make those record changes.

Second-order effects

Third-order effects

  • If registrar-side compromises keep recurring, DNS control becomes a recognized single point of failure for the whole web — pushing enterprises toward multi-registrar setups, hardened employee verification at registrars, and regulators treating domain infrastructure as critical attack surface rather than commodity hosting.

The trend: Domain registrars are shifting from being invisible plumbing to being prime targets, where a single socially engineered employee can redirect traffic for thousands of downstream sites.

Discussion

  • @briankrebs @briankrebs on x
    Exclusive: Fraudsters changed the email and DNS records for a number of cryptocurrency trading platforms this week, after successfully social engineering employees at GoDaddy, the world's largest domain name registrar. https://krebsonsecurity.com/ ... https://twitter.com/...
  • @stilgherrian @stilgherrian on x
    It's always DNS... https://twitter.com/...
  • @eastdakota Matthew Prince on x
    Secure your domain registration. Secure your DNS. Don't get those pieces correct and none of your other security will matter. https://twitter.com/...
  • @quinnypig Corey Quinn on x
    No daddy. https://twitter.com/...
  • @film_girl Christina Warren on x
    Holy shit. Of all the people you don't want social engineered into doing bad stuff it's the people that control access to DNS and domain names! https://twitter.com/...