source avatarСryptoTotem

Share

MakerDAO hit by a $543K exploit rooted in a 6-year-old bug On Oct 6, an attacker drained 200 $ETH (~$543K) from a legacy MakerDAO liquidation keeper contract — by weaponizing a vulnerability that's been sitting there since the 2020 "Black Thursday" crash. The flaw: one contract function had no access control, letting the attacker deploy a custom module and hijack the keeper's permissions inside MakerDAO's Vat. From there it escalated fast. The attacker settled four abandoned 2020 auctions that the keeper had won with zero bids but never paid for — unlocking 200 $ETH it was never entitled to. Funds hit the attacker's wallet within a minute of the exploit, and Tornado Cash mixing began just 6 minutes later, split into 10 $ETH batches. The root cause: missing access checks + a missing permission-revoke call after delegation. A textbook case of old, "dead" contract code becoming a live attack surface years later. 🔗Sourse (@CertiKAlert): https://t.co/YLXjeii3tl #MakerDAO #DeFi #CryptoHack #Ethereum #Web3Security

No.0 picture
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.