BasketDAO Hack

TOTAL LOST $1.2M
Medium Access Control Attacks ethereum

What happened

BasketDAO exploited due to smart contract vulnerability, resulting in a loss of approximately $107,000 worth of assets (42.55 ETH).

BasketDAO, a decentralized platform, experienced an exploit on January 17, 2024, on the Ethereum Mainnet. The exploit was caused by a smart contract vulnerability, specifically an arbitrary low-level call in the approval process. This flaw led to a user losing over $107,070 worth of assets, equivalent to 42.55 ETH.

The attacker was funded by FixedFloat and subsequently deposited the stolen funds into TornadoCash.

Attacker Address:

https://etherscan.io/address/0x63136677…14f8e8

Malicious Transaction:

https://etherscan.io/tx/0x97201900…6c15f6

Malicious Contract Address:

https://etherscan.io/address/0xae591916…738440

TornadoCash Deposit Transactions:

https://etherscan.io/tx/0x1fb689f8…033057

https://etherscan.io/tx/0xa95ee355…1f4a7d

Case & protocol details

Classification Other / Access Control
Protocol Type Indexes
Affected asset / contract BMI
Smart Contract Language Solidity
Official Website www.basketdao.org/
Protocol Twitter/X @BasketDAOOrg

Security review history

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.