BuildFinance Hack
What happened
Build Finance was an Ethereum venture-builder DAO governed by BUILD token holders. In February 2022, an attacker used the DAO's low-participation governance process to pass a proposal that transferred control of the BUILD token contract. With that control, the attacker minted BUILD, sold it into Uniswap and Balancer liquidity, and drained treasury-held METRIC.
Contemporary reporting estimated the proceeds at about $470,000.
Governance parameters and controls allowed a lightly observed proposal to transfer control of the token contract. A governance executor that can change minting authority or treasury control needs meaningful quorum, time-delayed execution, clear proposal notifications, and narrowly constrained actions for privileged changes.
Case & protocol details
How it happened
The takeover did not require a conventional contract-access exploit. The attacker accumulated enough voting power to meet Build Finance's low governance threshold and submitted a proposal granting control of the BUILD token contract. An earlier attempt drew attention and failed.
The subsequent proposal was not surfaced by the DAO's Discord notification bot, passed on February 10, and gave the attacker the ability to mint tokens and control the treasury. The attacker minted 1.1 million BUILD, sold the newly minted tokens into the project’s Uniswap and Balancer liquidity pools, removed 130,000 METRIC from the treasury, and later minted more BUILD. The important failure was the governance system’s ability to authorize an irreversible transfer of protocol control under weak quorum and monitoring conditions.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report twitter.com
- report Report twitter.com
- report Flipside Governance: examining the Build Finance exploit medium.com
- analysis Web Archive web.archive.org
- analysis Build Finance DAO suffers hostile governance takeover theblock.co
- analysis Build Finance DAO falls to governance takeover decrypt.co
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.