BasketDAO Hack
What happened
BasketDAO exploited due to smart contract vulnerability, resulting in a loss of approximately $107,000 worth of assets (42.55 ETH).
BasketDAO, a decentralized platform, experienced an exploit on January 17, 2024, on the Ethereum Mainnet. The exploit was caused by a smart contract vulnerability, specifically an arbitrary low-level call in the approval process. This flaw led to a user losing over $107,070 worth of assets, equivalent to 42.55 ETH.
The attacker was funded by FixedFloat and subsequently deposited the stolen funds into TornadoCash.
Attacker Address:
https://etherscan.io/address/0x63136677…14f8e8
Malicious Transaction:
https://etherscan.io/tx/0x97201900…6c15f6
Malicious Contract Address:
https://etherscan.io/address/0xae591916…738440
TornadoCash Deposit Transactions:
https://etherscan.io/tx/0x1fb689f8…033057
https://etherscan.io/tx/0xa95ee355…1f4a7d
Case & protocol details
Security review history
- HAECHI Audit Report
Evidence & learning
Sources and on-chain records
- report Report twitter.com
- analysis Web Archive archive.is
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.