What happened?
Starting in July 2024, attackers began hijacking domain names that customers had migrated from Google Domains to Squarespace after Google exited the registrar business in 2023 — and by mid-July, crypto phishing crews had turned at least a dozen of them, some tied to exchanges with daily volumes in the millions, into fake login pages harvesting wallet credentials. The root cause was procedural, not a zero-day: inherited accounts left unclaimed, combined with Squarespace’s reset flow honoring stale WHOIS mailboxes and domain-level DNS control granted to whichever account claimed the name. By 18 July, when this post publishes, web3 security firms had cataloged the campaign and registrants everywhere were re-learning an old lesson — domain ownership is account security.
Quick Answer: After Google Domains shut down and Squarespace inherited roughly 10 million domains in 2023, many owners never completed Squarespace account claiming. Attackers who could control legacy email addresses (or abuse Squarespace’s password-reset and domain-claim flows) took over unclaimed domains, redirected MX and A records, and pointed web3-linked names at crypto-drainer phishing pages. At least 12+ domains fell in July 2024 alone, including names used by exchanges and DeFi services. No vendor product was exploited in the classic sense — the victims’ assets were seized through the humble machinery of registrar account recovery.
The campaign’s selection of targets revealed its economics. Crypto-adjacent domains are valuable precisely because users trust bookmarked names: an exchange’s interface domain, an NFT marketplace’s help subdomain, a bridge’s status page. A drainer kit behind a legit-looking hostname converts at rates plain phishing can only dream of, so crews specialize in acquiring such hosts. Web3 researchers tracing the July wave noted the same infrastructure fingerprints across victims — drainer payloads, clandestine MX rewrites to catch password resets, and rapid issuance of TLS certificates for the impostor pages, courtesy of automated CAs that make any takeover look padlock-legitimate within minutes.
The Google Domains exit, one year later
Google announced its registrar wind-down in June 2023, selling the business and customer base to Squarespace, which committed to migrating every domain with renewal pricing locked for a year. The migration mechanics — domains moved as unclaimed assets attached to invoicing identities, with owners encouraged to create Squarespace accounts to manage them — left a gap between ownership on paper and control in practice. A meaningful fraction of the 10-million-name estate was never claimed into a secured account. Commission-chasing crews spent the following year enumerating that gap: names with live traffic, names in crypto use, names whose historical WHOIS contacts pointed at mailboxes attackers could register or reclaim.
| Date | Event |
|---|---|
| 2023-06 | Google announces Google Domains exit; Squarespace acquires registrar business and ~10M domains |
| 2023-08→2024-05 | Migrations proceed; unclaimed domains accumulate; Squarespace periodically locks domains to un-claimable states pending verification |
| 2024-07-10 circa | First hijack reports: web3-linked domains redirect to drainer pages; researchers begin tracking |
| 2024-07-15→17 | Coordinated disclosure pressure; Squarespace forces password resets and locks down affected claim flows; victim count passes a dozen |
| 2024-07-18 | Registrar confirms remediation; security press broadly covers the campaign; this post publishes amid cleanups |
Attack mechanics: possession is ten-tenths of the law
The takeover paths all converged on one prize — an authenticated Squarespace session with domain management rights. From there the attack is boring: change DNS records, re-point MX to capture mail, host a pixel-perfect clone of the original service, install a drainer. Some crews entered via stale-WHOIS mailbox control: domains whose registrant contacts predated the migration still listed addresses on mail providers that had since recycled or allowed re-registration. Others entered via reset-flow abuse on accounts with weak recovery posture. Registrar-side hardening — reset slickness for unclaimed assets tightened mid-campaign — closed specific doors, but the class of vulnerability (account state older than the owner’s attention) remained exactly where it has lived since the 1990s.
Why crypto took the headline damage
Traditional businesses lose SEO and email when a domain falls; crypto services lose the vault door’s signage. Several July victims were exchanges, token-swap frontends, or infrastructure providers whose users interact through the browser with real money. A spoofed exchange page asking for a seed phrase or a malicious transaction signature has direct, irreversible payout — no card-chargeback safety net — so drainer crews view each hijacked crypto hostname as a temporary money printer until detection kills it. The broader lesson travels beyond web3: any domain whose trust relationship with users is strong enough to survive a takeover (banks, government portals, internal tooling) carries the same latent risk when its registrar account rots.
- Inherited estates rot: every mass registrar migration creates unclaimed-assets pools; attackers inventory them patiently for high-value names.
- WHOIS mailboxes are keys: expired or recyclable registrant email addresses remain the cheapest takeover vector in domain security.
- TLS automation launders legitimacy: free automated certificates made impostor pages indistinguishable at the padlock level; users must judge content, not crypto.
- MX capture compounds: rewriting mail records during a takeover catches password resets for every service tied to the domain — turning one hijack into many.
FAQ
Was Squarespace itself hacked?
No system compromise at Squarespace has been demonstrated. The campaign abused legitimate account-recovery and domain-claim flows against weakly-claimed assets — attacker-controlled legacy mailboxes, unclaimed domains, loose reset posture. Squarespace responded with forced resets and claim-flow lockdowns for the affected population. Framing it as a Squarespace breach misses the durable lesson: registrar account hygiene is a customer-side control, at every registrar.
How do I tell if a domain I own was affected?
Audit, don’t assume. Log in to the registrar and verify: registrant/WHOIS contact mailboxes are ones you still control; DNS records match your inventory; MX still points to your mail provider; no unfamiliar accounts have domain permissions; certificates issued for the name (via public CT logs) all correspond to your hosting. Any surprise — especially CT-log certificates from issuers you never used during the July 2024 window — warrants immediate DNS review and credential rotation.
What is the permanent fix for this class of attack?
Registry lock where available (a high-friction, human-verified change path for critical names), registrar locks and 2FA on the account, corporate-domain asset inventories with ownership reviews, and mailboxes-on-your-own-domain circularity broken by keeping at least one registrar contact on an independent provider. High-value names deserve the same change-control as production infrastructure — because as July 2024 showed, that is exactly what they are.
The cs-research diet: why this story ran on web3 desks first
Outlets and researchers noticed the campaign through its monetization, not its mechanism — the first hijacked domains served crypto drainers, so blockchain-security firms saw the flows before anyone saw the DNS. That visibility skew is worth remembering: infrastructure attacks surface wherever the money moves first. Had the same unclaimed-domain pool been harvested for corporate espionage or SEO spam instead, discovery might have taken months longer. The July wave was detected fast because its thieves were in a hurry — a silver lining with a shelf life.
Coda: the 10-million-name experiment
The Google Domains exit was, in retrospect, a natural experiment in what happens when ten million digital assets change custody with nothing but email nudges to shepherd owners. The result: a long tail of unclaimed names, a year-long quiet inventory by opportunists, a concentrated burst of hijacks, and a hurried industry cleanup. The next mass registrar consolidation will run the same experiment again. Owners who claimed, locked, and contact-audited their names in 2024 will be the control group that keeps its domains; everyone else is the treatment group. Registrar choice, it turns out, is a security decision — and domain dashboards deserve the same operational seriousness as production consoles, because to an attacker there is no difference at all.
