---
title: "We screwed up and we own it: The eth.limo sh*tshow is on us."
type: "post"
post_id: "186171"
slug: "we-screwed-up-and-we-own-it-the-eth-limo-shtshow-is-on-us"
canonical: "https://easydns.com/blog/2026/04/18/we-screwed-up-and-we-own-it-the-eth-limo-shtshow-is-on-us/"
markdown_url: "https://easydns.com/blog/2026/04/18/we-screwed-up-and-we-own-it-the-eth-limo-shtshow-is-on-us.md"
json_url: "https://easydns.com/blog/2026/04/18/we-screwed-up-and-we-own-it-the-eth-limo-shtshow-is-on-us.json"
txt_url: "https://easydns.com/blog/2026/04/18/we-screwed-up-and-we-own-it-the-eth-limo-shtshow-is-on-us.txt"
published: "2026-04-18T16:19:09+00:00"
modified: "2026-04-18T17:49:20+00:00"
author: "Mark E. Jeftovic"
categories:
  - "Mea Culpa"
tags:
site_name: "easyDNS"
publisher: ""
language: "en-US"
generator: "easyPress Markdown"
generator_version: "1.0.3"
---
It’s never a good sign when you wake up on a Saturday morning and realize your phone has been blowing up since about 4am.

Instead of spewing out the usual GPT-generated platitudes around “we take your security very seriously” (even though that *is* true), I’m just going to lay it out here.

Eth.limo was hijacked via a social engineering attack
-----------------------------------------------------

And a highly sophisticated one, at that.

This would mark the first successful social engineering attack against an easyDNS client in our 28 year history. There have been countless attempts. In the past we’ve seen disgruntled employees (who already had access) hijack their employer accounts et al… but never have we been fooled into enacting an account recovery process that turned out to be bogus.

Yesterday, that happened to **eth.limo**, the ENS gateway domain that provides a web2 accessible bridge to to the approximately 2 million .eth domain names that run over Ethereum Name Service (ENS).

I don’t want to get into the gory details of how this happened, we are obviously conducting our post-mortem and have already made process changes that prevent a recurrence of this incident.

In eth.limo’s case, we will be migrating them to Domainsure, which has a security posture more suited toward enterprise and high-value fintech domains (TL;DR there is no mechanism for an “account recovery” on Domainsure, it’s not a thing).

None of the above softens the blow or dampens the sting of losing an unblemished record.

What eth.limo did right (a.k.a DNSSEC saves the day)
----------------------------------------------------

DNSSEC was enabled for their domain, when the attackers attempted to flip their nameservers, presumably to effect some manner of phishing or malware injection attack, DNSSEC-aware resolvers (which most are these days) began dropping queries.

This is as it should be, and it demonstrated the value of DNSSEC-signing your domains.

On behalf of everyone here, I apologize to the eth.limo team and the wider Ethereum community. ENS has always had a special place in our heart as the first registrar to enable ENS linking to web2 domains and we’ve been involved in the space since 2017.

Despite the “L”, I’ll still maintain that we’re the one of the few registrars out here who has a deep understanding of the unique attack surfaces and security requirements for crypto, fintech and Bitcoin related domains.

This is a huge black eye for us, and we know it.

The eth.limo [post-mortem is here.](https://x.com/eth_limo/status/2045552916157563148)

— Sincerely
Mark E. Jeftovic, co-founder and CEO
markjr@myprivacy.ca

*(No other customers were impacted, no easyDNS systems or data have been compromised, this incident was confined to human processes on a single account).*
