GoDaddy confirms some of its staff fell for a social engineering scam, after hackers changed the email and DNS records for a number of crypto trading platforms
Fraudsters redirected email and web traffic destined for several cryptocurrency trading platforms over the past week.
Context & Ripple Effects
This is not GoDaddy's first security story, and the pattern is what makes it matter. Researchers had already tied widely received spam campaigns to a previously detailed weakness at GoDaddy.com, and a year later the company reset passwords on hundreds of compromised accounts while taking down more than 15,000 abused subdomains.
First-order effects
- The immediate victims are the crypto trading platforms whose email and web traffic was silently rerouted once attackers altered their DNS records — customers saw attacker-controlled destinations with no visible warning.
- GoDaddy's own staff are now the confirmed attack surface: the company says social engineering of employees, not a technical exploit, is what gave hackers the access to make those record changes.
Second-order effects
- Crypto exchanges and other high-value domain holders face pressure to move DNS away from any single registrar or add registrar-level locks, since the weakest link proved to be support staff rather than customer credentials.
- Every subsequent disclosure compounds the reputational cost: the 2021 SEC filing revealing a third party inside Managed WordPress hosting with access to up to 1.2M customer numbers and admin passwords, followed by the multiyear breach discovered in December 2022 involving stolen source code and malware, turns each new incident into evidence for a pattern rather than an isolated lapse.
Third-order effects
- If registrar-side compromises keep recurring, DNS control becomes a recognized single point of failure for the whole web — pushing enterprises toward multi-registrar setups, hardened employee verification at registrars, and regulators treating domain infrastructure as critical attack surface rather than commodity hosting.
The trend: Domain registrars are shifting from being invisible plumbing to being prime targets, where a single socially engineered employee can redirect traffic for thousands of downstream sites.