The decentralized finance protocol Neutrl has officially resumed its operations after completing a critical migration of its digital infrastructure. Following a recent DNS hijacking incident, the project’s development team transitioned to a new official domain and a more secure DNS service provider. According to the latest updates as of March 21, 2026, the protocol's smart contracts have been unpaused, allowing users to once again interact with the platform’s financial services in a secure environment.
Security Framework and Asset Protection
Despite the compromise of the project's frontend infrastructure, the protocol’s core financial architecture remained intact. Neutrl officials confirmed that all user funds are safe, as the Protocol's Net Asset Value (NAV) and reserve assets are managed through a sophisticated custody framework. This system utilizes isolated custody wallets and an Over-the-Counter Settlement (OES) mechanism to ensure that even in the event of a website breach, the underlying liquidity remains unreachable to unauthorized parties.
- All reserve assets are stored in isolated custody to mitigate infrastructure risks.
- The OES mechanism provides an additional layer of security for high-value transactions.
- Smart contracts were temporarily paused to prevent malicious interactions during the migration.
Required User Actions and Risk Mitigation
While the new domain is fully functional, the original domain remains a security risk and will be gradually phased out. Security analysts recommend that any users who interacted with the platform during the period of the DNS hijacking take immediate steps to secure their wallets.
Users are specifically warned not to visit the old URL, as it may still host malicious scripts intended to drain digital assets.
Users who have interacted with the affected domain are advised to revoke relevant authorizations, including Permit2 authorizations to specified malicious addresses, and to clear all unknown authorizations.
The successful restoration of Neutrl highlights the ongoing importance of frontend security within the DeFi ecosystem. By decoupling the user interface from the underlying smart contracts and asset custody, the protocol managed to preserve its Total Value Locked (TVL) despite a direct attack on its web presence. Users are encouraged to verify all transaction details through block explorers before signing permissions on the newly established domain.
Frequently Asked Questions
Quick answers to the most common questions about this topic.