DNS/CDN/frontend hash drift
Dolomite's assessment for RD-F-105 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
T-09 phase-2 signal tier. Official domain: dolomite.io. 2020 historical incident: API key exposed on frontend (add.xyz statement, 2020-07-29) — pre-v2 architecture, unrelated to current DNS/frontend monitoring surface. No 2025-2026 DNS/CDN drift incident found. No published frontend hash or IPFS CID found in Dolomite docs. No change-management allowlist publicly documented. Yellow: no active drift detected, but protocol does not publish a frontend hash baseline, meaning drift could go undetected without an external monitoring stack.
Sources #
- URLStatement on the Dolomite.io Breachadd.xyz Medium: 2020 API key exposure on Dolomite frontend (historical, pre-v2)retrieved 2026-05-16
- Dolomite Documentationdocs.dolomite.io: no frontend hash or IPFS CID published in current documentationretrieved 2026-05-16
Methodology #
Detect whether the hash of production frontend JS changes versus the prior published hash, or a DNS config change is detected.
See the full factor methodology and distribution across all protocols →