Several DeFi apps have been targeted by a domain hijacker who may have discovered an exploit in Squarespace’s registry system, according to Blockaid. The attack, which occurred on July 11, involved the DNS registry control of Compound Finance and attempted control of Celer Network’s registry. Blockaid's preliminary investigation suggests that the attacker is targeting domains provided by Squarespace, putting any DeFi app with a Squarespace domain at risk. The attack was first noticed when the Compound interface began redirecting to a malicious site equipped with a drainer app designed to steal users' tokens. Security firm Blockaid warned that multiple DeFi front ends are at risk, and a list of potentially affected domains includes over 100 DeFi protocols. MetaMask is warning users of compromised apps associated with the attack.