ENS Issues Proactive Security Advisory

The Ethereum Name Service (ENS) operations team has released a security advisory regarding a potential vulnerability identified within its ecosystem. The concern is currently linked to a specific third-party domain resolution pathway.

Scope and Current Impact Assessment

According to the official communication, the security consideration is presently confined to the resolution service provided via the eth.limo domain. The ENS team has explicitly stated that the alternative eth.link service remains unaffected. Most importantly, the core ENS protocol—including domain registration, management, and primary resolution—continues to operate securely without interruption, ensuring the safety of users' .eth domain holdings.

Official Response and User Guidance

As a precautionary measure of the highest order, the ENS team has immediately initiated a detailed investigation into the involved DNS registrar to determine the root cause. Until the investigation is complete and the issue is fully resolved, users are strongly advised to adhere to the following guidelines:

  • Avoid clicking on or accessing any links ending with eth.limo for the time being.
  • Exercise caution and verify the gateway or front-end address when interacting with ENS services.
  • Monitor official ENS social media channels and announcement platforms for the latest updates on the investigation and resolution.

The ENS team emphasized that this advisory is a preventive action, underscoring their commitment to user asset security. They pledged to provide timely and transparent updates as the situation develops.