BasketDAO Hack
What happened
On 30 March 2022 an attacker drained tokens from users who had approved BasketDAO's BMIZapper contract on Ethereum. BMIZapper was a helper for minting BasketDAO's BMI index token. It could make external calls built from caller-supplied input, so the attacker used it to call transferFrom on tokens that users had approved to the zapper and send the funds to themselves. Reported losses are about $1.1 million (Fairyproof) to $1.2 million (Revoke.cash).
BasketDAO told users on 30 March to revoke all approvals for BMIZapper (0x4622aFF8E521A444C9301dA0efD05f6b482221b8). A day later it reported a similar vulnerability in BMIBurner (0x01A903c12A2Dd87A5410173A29543504DF8bD14B). The project had already been winding down after an October 2021 exploit of a different helper contract. Because the contracts stayed on-chain, wallets that never revoked their approvals could still be drained years later.
How it happened
- Users who minted BMI through
BMIZapperhad given it ERC-20 approvals, often unlimited. - The zapper's
_primitiveToBMIpath made a low-levelcallusing caller-supplied target and data, and did not validate them. - The attacker built calldata so that the zapper called
transferFromon approved tokens, moving each victim's balance to an attacker address. - The attacker repeated this for approving wallets, taking about $1.1M to $1.2M, until users revoked their approvals.
Protocol details
Security review history
- HAECHI Audit View report
Evidence
- report BasketDAO on X: BMIZapper vulnerability, revoke approvals (fxtwitter mirror) x.com
- report BasketDAO on X: similar vulnerability in BMIBurner (fxtwitter mirror) x.com
- report Weekly Blockchain Security Report by Fairyproof - Mar 28 to Apr 3 fairyproof.substack.com
- analysis DeFiLlama defillama.com
- analysis 2022 BasketDAO Hack: Check If You're Affected revoke.cash
- analysis BasketDAO Peripheral Exploit Incident (Medium RSS) basketdao.medium.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.