OpenEden has issued an urgent warning after detecting a suspected DNS compromise affecting its main website and portal. The platform said users who enter OpenEden URLs in a browser could be redirected to malicious pages, creating a risk of wallet theft if they connect a wallet or sign transactions.
Users told not to access any OpenEden domains
According to the team, the issue appears to involve tampering with the domain name system that routes traffic to its web properties. That means a legitimate-looking URL may no longer lead to the intended destination. In crypto, that can be enough for attackers to capture approvals, signatures, or other wallet permissions.
OpenEden’s instruction was direct: do not visit or interact with any OpenEden domain until the issue has been fixed.
Onchain reserves said to be unaffected
At the same time, OpenEden said all onchain reserve assets remain safe and were not impacted by the incident. Users can independently verify the backing of the USDO stablecoin and the TBILL fund through Chainlink Proof of Reserve.
OpenEden describes itself as a leading RWA tokenization platform. Its tokenized U.S. Treasury fund, TBILL, is managed by BNY and is described by the company as the first onchain treasury product to receive both an “AA+” rating from S&P and an “A” rating from Moody’s. The company also said the fund ranks first by size in Asia and Europe.
A familiar attack route in crypto
DNS hijacking has hit the crypto sector before. Attackers can compromise a domain registrar or DNS provider and redirect traffic from a legitimate site to a phishing page without changing the URL users expect to see. DeFi protocols including Balancer and Curve Finance have faced similar incidents in the past.
OpenEden said it is investigating the matter and will release more updates as they become available.

