BasketDAO Hack

Reported loss $1.2M
Ethereum
Arbitrary External Call

What happened

On 30 March 2022 an attacker drained tokens from users who had approved BasketDAO's BMIZapper contract on Ethereum. BMIZapper was a helper for minting BasketDAO's BMI index token. It could make external calls built from caller-supplied input, so the attacker used it to call transferFrom on tokens that users had approved to the zapper and send the funds to themselves. Reported losses are about $1.1 million (Fairyproof) to $1.2 million (Revoke.cash).

BasketDAO told users on 30 March to revoke all approvals for BMIZapper (0x4622aFF8E521A444C9301dA0efD05f6b482221b8). A day later it reported a similar vulnerability in BMIBurner (0x01A903c12A2Dd87A5410173A29543504DF8bD14B). The project had already been winding down after an October 2021 exploit of a different helper contract. Because the contracts stayed on-chain, wallets that never revoked their approvals could still be drained years later.

How it happened

  1. Users who minted BMI through BMIZapper had given it ERC-20 approvals, often unlimited.
  2. The zapper's _primitiveToBMI path made a low-level call using caller-supplied target and data, and did not validate them.
  3. The attacker built calldata so that the zapper called transferFrom on approved tokens, moving each victim's balance to an attacker address.
  4. The attacker repeated this for approving wallets, taking about $1.1M to $1.2M, until users revoked their approvals.

Protocol details

Classification Access Control
Protocol Type Indexes
Implementation language Solidity
Protocol links @BasketDAOOrg

Security review history

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.