AzukiDAO Hack

TOTAL LOST $68K
Low Replay Attacks ethereum

What happened

AzukiDAO, an Ethereum-based DAO project, was exploited in a replay attack resulting in a loss of 72,693 $USD.

AzukiDAO's governance token contract (Bean) was exploited due to a contract vulnerability that was not properly checking the signatureClaimed variable, leading to replay attacks. Two attackers exploited this vulnerability and made a combined profit of approximately 35 ETH. The exploit has been halted with the contract currently in a paused state.

The funds are currently remaining in the attacker's address as ETH.

Attacker Address:

https://etherscan.io/address/0x85d231c2…64c75e

Malicious Transaction Example:

https://etherscan.io/tx/0x4c50c1da…e84acc

Case & protocol details

Classification Protocol Logic / Input Validation / NFT,Token
Protocol Type Exploit/Other
Affected asset / contract Bean
Smart Contract Language Solidity
Official Website azukidao.io/
Protocol Twitter/X @_AzukiDAO

Evidence & learning

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.