Library · Crypto, word by word · Scams and security
What is a front-end hijack?
A front-end hijack is an attack on the website of a crypto app rather than its smart contracts. The attacker takes over the domain, the hosting or a code library the site loads, so people visiting the real address see a normal-looking page that asks them to sign transactions sending funds to the attacker.
What it means for you
Typing the correct address is not enough here, because the address itself is serving the attack. What protects you is reading each request in your wallet: the contract you are calling, the spender of any approval and the amount. A request for an unlimited approval or a transfer you did not intend is a reason to reject it, even on a site you have used for years.
How it works
The contracts on-chain are untouched; the attack sits in what the browser loads. CISA describes attackers who steal domain registrar credentials and repoint a domain's DNS records to servers they control, sometimes obtaining certificates so the padlock still appears. A review of Web3 supply-chain security adds two other routes: compromising the hosting so deployed files are altered, and poisoning a JavaScript dependency so it changes recipient addresses or transaction parameters before the user signs. Unlike phishing, which relies on a lookalike address, the page here sits at the genuine one.
Sources: CISA: DNS infrastructure hijacking campaign, Monperrus, Software Supply Chain Security of Web3 (arXiv) · checked 4 October 2026
Often confused with
Related words
Educational content, not financial advice. Written by hand and checked against the source named above. Something wrong? Tell us and we reply within two business days.