Namefi
Back to all glossary terms

Domain Hijacking

The theft of a domain by gaining unauthorized control of its registrar account or registration.

Namefi TeamNamefi TeamAuthorVictor ZhouVictor ZhouEditorJune 22, 2026
  • glossary

Domain hijacking is the unauthorized seizure of a domain name by an attacker who gains control of the owning registrar account — typically through phishing, credential stuffing, or social engineering against registrar support staff. Once inside the account, the attacker can change nameservers to redirect traffic, disable registry lock protections, or initiate a transfer to lock the legitimate owner out entirely, which is why it often overlaps with outright domain theft. Defenses include enabling a transfer lock, using hardware-key two-factor authentication, opting into registry-level locking for high-value names, and keeping registrar contact details current so recovery emails reach you.

Related keywords

  • domain hijacking
  • account compromise
  • domain theft
  • registrar security
  • unauthorized transfer

Contributors

Namefi TeamAuthor
Namefi Team • Namefi

Namefi is a collective of engineers, designers, and operators who obsess over building tools that make managing your onchain domain names effortless.

Victor ZhouEditor
Founder & Standards Editor • Namefi

Victor Zhou is a technology founder and standards editor focused on digital identity and trust. He founded Namefi, edits Ethereum Improvement Proposals, and previously led smart-contract architecture work at Google Labs.

His work sits at the intersection of naming, ownership, and the systems people use to establish identity online. That perspective makes him especially interested in the way names move between personal meaning, public recognition, and digital infrastructure.

For Namefi, Victor edits and writes about domains as durable digital identity: how names become ownable onchain assets, how tokenization changes custody and trust, and what naming can learn from the systems people use to establish identity online.