Compound Finance landing page compromised with phishing redirect on App button; protocol contracts unaffected but users at risk.
Security & Exploits ·
The "App" button on Compound Finance's landing page is redirecting users to a phishing domain, posing a risk to those who click it or interact with applications loaded through it. The protocol's smart contracts appear unaffected, with the issue limited to the website's frontend. Users who have already interacted with the compromised link are advised to revoke token approvals and move funds from affected wallets.