ENS War Stories: Securing Web3 from Web2-Based Attacks by Alexander Urbelis | Devcon SEA
Devcon·Thu, Oct 9, 2025, 12:00 AM
Speaker
Web3 is not an island. Every day, threat actors try to exploit web2 domains to target web3 entities. This talk recounts ENS' war stories / lessons of battling threats in the DNS, including: - Detecting early-stage attacks on web3 entities in the DNS - How we unraveled a campaign of over 2,500+ web2 domains targeting web3 and defi entities - Legal and technical remedies to combat web2-based threats (and their limitations) - Why the ecosystem must come together to share intel and resources Speaker(s): Alexander Urbelis Skill level: Intermediate Track: Security Keywords: Collective Intelligence, Security, Best Practices, user, safety Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/
Transcript
[Music] [Music] it is on okay all right that's a little bit better [Applause] fantastic good afternoon Bangkok good afternoon Devcon I'm very excited to be here my name is Alex orelis I'm the general counsel of the ethereum foundation in the ciso this is my first Devcon so thank you for having having me appreciate that yeah you're supposed to applaud there we go very good very very good excellent um welcome to the lightning track I think there was supposed to be an MC so I'm your um your kind of you know I'm your MC over here okay all right we got the lights going I think everything's going to be okay hopefully slides disappeared though so so oh there we go all right so we'll kick this off um everything seems to be going all right all right so um show of hands here how many people were at friends day yesterday oh my God amazing amazing I love it I gotta tell you I just want to give a shout out to ens all my peoples I mean we had an amazing amazing event yesterday we had vitalic there we announced name chain our L2 we had Jesse from I mean it was just such a great great U opportunity for all of us to come together and in as much as this talk is about things that are kind of scary about these web 2 based attacks on our web 3 ecosystem this is also about bringing us together and and very much highlights some of the cool things that we are doing within ens that's behind the scenes and is protective of our entire ecosystem and things that we're also building upon so um since I'm new to this ecosystem here a tiny little bit about me this talk will make a lot more sense if you understand that I was a hacker before I was a lawyer so according to my mother that means I went from bad to worse okay um but I've also done both sides of the fence I've been a lawyer and I've also been a siso before I joined ens I was the siso of the NFL in the United States the National Football League and and I've you I've done a couple of things in defense and intelligence so that's where the the background is here and I want to call up to the stage one of my colleagues Malika Gaza to talk about herself uh hi everyone I'm Malika I'm a legal research associate at um ens so I'm a lawyer I'm not a hacker but I've never i' never been a hacker always been a lawyer I uh hold a legal um master degree in intellectual property and information law and I also uh participated in the world intellectual organization academy uh where I've deep in my knowledge in blockchain excellent fantastic and we'll hear from Malik a little bit later on uh in the presentation as well so let's jump into this and let's talk about this from the from the start we're going to talk about the DNS you know it's one letter away from ens except it's a hell of a lot more dangerous right so the DNS been around the domain name system has been around for a really long time and there's just Decades of abuse and um and and and it's very difficult to mitigate that kind of abuse right people have gotten really good at it right so one of the things that we did within ens and this goes back to my hacker Roots is that um many years ago I created a dns-based threat intelligence system that looks for early stage indicators of attacks on companies originating in the domain name system so we we refocus some of that work using regular expressions and pattern recognition to find a tax on users of ens and what we found was that these bad guys really abounded within the DNS so you see domains like at the bottom airdrop d. domains these are things that were cropping up on a daily basis um we found that these attacks would launch usually from some kind of compromised account on Twitter they were propelled by some kind of compromised account link tree was was very often used to to uh guide people over and ultimately what would happen was that somebody would fall for some kind of fake airdrop or a claim um or to renew a domain and it would connect them with a malicious smart contract on the blockchain usually some kind of wallet drainer the other thing that was interesting was these attacks were stood up really really quickly this is what the attacks generally look like and it was one after another after another they were really persistent the volume and velocity of the attacks that we were finding in the domain name system were was really astounding so this we realized pretty quickly was was an issue for the entire web 3 ecosystem as well because it's an onboarding issue if we're going to onboard the next 100 million or next billion users into web 3 and defi we need to make the space a lot more secure and you can see here what happens is you know there's a chat now button there's a there's a little bot net over there but they also have these wallet connectors for metamask coinbase wallet trust treasure all of this so um and they were obviously replicating the look and feel of. domains now one of the things that was really bizarre was that when we started to amass a lot of intelligence and data within the DNS about these attacks we found one consistent thread and this has to do with the who is Data of domain names so most of you will know about gdpr um gdpr is the Privacy Law in the uh that's obviously applicable in the united uh the European Union but applies extra territorially so domain registrars because there's personal information in the who is data sets would have to mask all of the the information about the registrants but gdpr applies to people it does not apply to organizations so it doesn't protect companies so there's one field in the who is data for all of these attacks that was not masked and we found that there was a consistent thread of a bogus company called Lolita LLC throughout all of these domains that we were finding that were attacking ens so what we were able to do was take that data about Lolita LLC and pivot on it within the domain name system and find over 2,200 domain names that were targeting not just DNS but the wider web 3 and Def defi system and these are actual domains that belong to this persistent threat actor here I mean it's kind of massive what we've been able to find and these are all domains that were registered from January of this year uh some of these have not even been launched yet some of these are are going to host attacks on companies that some of us may work for or have an interest in um at some point maybe today maybe tomorrow maybe a week from now but I want to talk a little bit about how we've been tracking these particular types of threats so tracking and and threat detection here um what we found was that there's consistent infrastructure associated with these attacks they always hid behind Cloud flare they always hide the host behind Cloud flare so what I did was I wrote a script A A bash script this is you know kind of hacker code that put together and for every 10 minutes I would go through the 2,200 or so domains that we found and create a list of every domain that was configured to look uh with name server records pointing to Cloud flare and then if I found new NS records that were pointing to Cloud flare that indicated that an attack was about to be stood up against that company at that point you can then usually scarf down all of the data that's in an open directory on that particular web server gain actionable intelligence about what's about to happen maybe even some kind of ttps and indicators about this particular threat actor but so looking at the NS records here was an actual um a great early warning system for us now here's using using that particular uh detection system these These are actual attacks on the web 3 and defi ecosystem that we found and took screenshots of over the last several months so you can see they all look very very similar to the attack on ens as well um but the the thing was amazing about this was that they're stood up so quickly sometimes the domain would be registered and within hours you see a live attack uh being stood up and and and and propelled so what do we do about all this what do we do about it I want to call up mikica for a second and talk about some of the things that we're doing at ens on a daily basis so what do we actually do we um elaborated a few um strategies so first of first of all we do takedowns so as soon as we spot any malicious activity any uh malicious actor we report fraudulent uh websites to hosting providers like cloudflare and uh to domain registers uh next we also do Blacklist so we actually uh add all of these fraudulent websites to uh Blacklist and we block the access and um limit the spread of uh fishing uh we we also submit uh regular reports to um antivirus providers to security uh teams and platforms like an efficient um working group and uh for a longterm uh control we also put uh forward the uh UD uh udrp udrp is a uniform domain named disate um uh resolution policy so it's uh essentially a formal complaint that we uh file and um so this complaint let us uh transfer the uh domain names back to in in's ownership thank you appreciate that LE and and udps here this is this is a a screenshot of one of the udps that we filed on behalf of enss where we took out a whole bunch of these bad guy domains um but that takes weeks it's not fast enough to do that right so here's where I want to end this is my modest proposal for the ecosystem and for the community here and and and really I think showcases some of the cool stuff that we're we're doing behind the scenes at ens we want to share this intelligence with all you we want to put the 2,200 plus domains into all of your hands so that you can begin to block and tackle these types of domains we want to pull our resources together we also think there is a way that we can reclaim all of these domains so here's where we go on the offense the udrp system that Malika just uh identified and talked about right it takes a little while takes a couple of weeks for this to happen but there are very few cases where there have been multiple plaintiffs or multiple complainants going after a large number of domains at ens we've reclaimed a whole bunch of domains through udps but not to together as an ecosystem there is an opportunity now especially with the world intellectual property organization to change some of the laws about multiple complaintants filing these because we have common grievances because we have a clear registration pattern from this threat actor that is going after digital assets of our users and we have the same exact rights at issues we can come together and file one complaint that may be able to take out all 2200 of these particular domains and if we do that there's going to be a tremendous Network effect it will send a a shot across the bow to this particular thread actor which is very a very sophisticated and advanced persistent threat and what it'll also allow us to do is maybe something akin to what the FBI does when they take down botn Nets put a banner up so that anybody who goes to that particular site knows that it was reclaimed and it was reclaimed by us as an organization or within our ecosystem that sends a clear warning there but more importantly we'll get the registrant information from about how they registered this particular name all of the information that they used and then we'll be in possession of those domains and we can actually host them ourselves once we have those domains we can look at the web server logs and a lot of you that you know go back to the 90s and web developers you'll remember these server environment variables one in particular httpcore refer which shows you how somebody got to a particular domain what links they clicked that's intelligence that can be really actionable to the entire community and will allow us to push the fight back further so that we're not reacting when domains are registered and attacking our users we can go after their infrastructure one level before it's hit it hits us so that's basically uh what I wanted to show you uh we really thank you for listening here we're opening up the floor to questions if we have any more time we might have gone over but please do be in touch with Malika and me if you would like to share this information come together and take out these bad guys thank you for listening [Applause]
Automatic transcript — names and jargon may be misspelled.