Close Menu
Altcoinvest
    What's Hot

    Is BTC Bracing for Another ‘Black Swan’ Event?

    May 9, 2026

    What Does ETH Need to Surge Past $3,000 Again as Whales Are Abandoning Ship?

    May 9, 2026

    Spot Bitcoin ETFs Log 6th Straight Week of Net Inflows for First Time Since August

    May 9, 2026
    Facebook X (Twitter) Instagram
    Altcoinvest
    • Bitcoin
    • Altcoins
    • Exchanges
    • Youtube
    • Crypto Wallets
    • Learn Crypto
    • bitcoinBitcoin(BTC)$80,330.000.22%
    • ethereumEthereum(ETH)$2,313.871.03%
    • tetherTether(USDT)$1.000.00%
    • rippleXRP(XRP)$1.422.28%
    • binancecoinBNB(BNB)$650.211.60%
    • usd-coinUSDC(USDC)$1.000.00%
    • solanaSolana(SOL)$93.585.58%
    • tronTRON(TRX)$0.3523551.21%
    • Figure HelocFigure Heloc(FIGR_HELOC)$1.032.53%
    • dogecoinDogecoin(DOGE)$0.1097102.20%
    Altcoinvest
    Home»Bitcoin»Steakhouse Financial Confirms DNS Hijack, Says No User Funds Were Lost
    Steakhouse Financial Confirms DNS Hijack, Says No User Funds Were Lost
    Bitcoin

    Steakhouse Financial Confirms DNS Hijack, Says No User Funds Were Lost

    April 11, 2026
    Share
    Facebook Twitter LinkedIn Pinterest Email

    TLDR:

    • Attackers socially engineered OVHcloud support to remove hardware 2FA, enabling full account access within an hour.
    • The phishing site used an Inferno Drainer kit and ran live for roughly four hours on March 30, 2026.
    • ICANN’s five-day domain transfer lock gave Steakhouse Financial time to cancel an outbound transfer filed by the attacker.
    • Steakhouse vaults on Morpho operated independently throughout; no depositor funds were at risk at any point.

    A social engineering attack briefly redirected Steakhouse Financial’s website to a phishing page on March 30, 2026. 

    Attackers manipulated the domain registrar’s support team to strip account security protections. The phishing site ran for roughly four hours before the team reclaimed control. No user funds were lost, and no onchain contracts were touched.

    How Attackers Broke Into Steakhouse Financial’s Domain Registrar

    The attacker called OVHcloud, the domain registrar used by Steakhouse Financial, and posed as the account owner. They provided enough personal information to pass OVH’s phone-based identity check. 

    An OVH support agent then removed the hardware-based two-factor authentication on the account.

    Within seconds of logging in, the attacker ran automated scripts. These deleted every second-factor device on the account and enrolled their own. The speed pointed to a pre-planned operation.

    The attacker then redirected the domain’s nameservers to servers under their control. 

    They pointed the site’s A records to a cloned version of the Steakhouse website hosted on Hostinger. That cloned site carried a wallet drainer linked to Inferno Drainer, a known drainer-as-a-service operation.

    Let’s Encrypt TLS certificates were obtained within minutes. This made the phishing site appear legitimate to standard browsers. Wallet extensions from Phantom, MetaMask, and Rabby flagged the site as malicious independently and quickly.

    Steakhouse Financial Regained Control Within Hours, Funds Remained Safe

    Steakhouse Financial’s team spotted the unauthorized email-change notification at 08:47 UTC and contacted OVH immediately. The phishing site went live around 09:59 UTC. 

    The team posted a public warning on X at 10:34 UTC, under 30 minutes after the site became operational.

    The Security Alliance (SEAL) was brought in at 11:25 UTC while the attack was still active. The team worked across multiple parallel tracks. These included account recovery, DNS forensics, and transfer cancellation.

    The attacker had filed an outbound domain transfer. ICANN’s five-day transfer timelock gave the team time to cancel it.

    The team contacted Hostinger directly to reject the transfer on the receiving end. Hostinger later confirmed the offending account was frozen and closed.

    By 12:56 UTC, the team had reclaimed the OVH account. DNS was fully restored by approximately 13:55 UTC. Steakhouse Financial confirmed all domains were safe to use by April 1.

    The company has since migrated to a registrar supporting hardware-key MFA and registrar-level locks. A continuous DNS monitoring system now watches all Steakhouse domains in real time. According to the post-mortem published by Steakhouse Financial on X, a full vendor security review process is now being established across all supply-chain vendors.

    Adrian Cachinero Vasiljevic, the partner responsible for operations at Steakhouse Financial, issued a personal apology. He stated that identifying this attack vector was his responsibility and committed to driving the security hardening work going forward.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    What Does ETH Need to Surge Past $3,000 Again as Whales Are Abandoning Ship?

    May 9, 2026

    Strategy CEO Phong Le prioritizes math over ideology in Bitcoin sales

    May 9, 2026

    Payward files application for OCC National Trust Company, deepening commitment to regulated digital asset infrastructure

    May 9, 2026

    Can ARMA Turn the Strategic Bitcoin Reserve Into Law?

    May 9, 2026
    Add A Comment

    Comments are closed.

    Tweets by InfoAltcoinvest

    Top Posts

    What Does ETH Need to Surge Past $3,000 Again as Whales Are Abandoning Ship?

    May 9, 2026

    Strategy CEO Phong Le prioritizes math over ideology in Bitcoin sales

    May 9, 2026

    Payward files application for OCC National Trust Company, deepening commitment to regulated digital asset infrastructure

    May 9, 2026

    South Korea to Extend Crypto Travel Rule to Sub-$700 Transactions in AML Clampdown

    November 28, 2025

    Taiwan to become close AI strategic partner with US following new investment deal

    January 16, 2026

    Trump declares global tariff hike to 15% following court setback

    February 22, 2026

    URGENT: 3 Reasons Bitcoin Will Have A Huge Move Soon!

    December 9, 2025

    Altcoinvest is a leading platform dedicated to providing the latest news and insights on the dynamic world of cryptocurrencies.

    We're social. Connect with us:

    Facebook X (Twitter)
    Top Insights

    Is BTC Bracing for Another ‘Black Swan’ Event?

    May 9, 2026

    What Does ETH Need to Surge Past $3,000 Again as Whales Are Abandoning Ship?

    May 9, 2026

    Spot Bitcoin ETFs Log 6th Straight Week of Net Inflows for First Time Since August

    May 9, 2026
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.


    Facebook X (Twitter)
    • Home
    • About us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions
    © 2026 altcoinvest.com

    Type above and press Enter to search. Press Esc to cancel.