DAO Maker SHO Hack (August 2021)

REPORTED LOSS $7.0M
Medium Private Key Compromised (Unknown Method) ethereum

What happened

DAO Maker's August 2021 incident drained approximately $7 million in USDC from its Strong Holder Offering (SHO) deposit system. The CEO said two administrative multisignature wallets were compromised. DAO Maker said its vault and vesting contracts were unaffected.

Technical Root Cause

Administrative authority was used to grant withdrawal permissions in the SHO/Essential contract system. The on-chain role grants explain the withdrawals, but do not establish how the administrative wallets were initially compromised.

Case & protocol details

Classification Infrastructure / Stablecoin,Other / Access Control
Protocol Type Services
Affected asset / contract DAO
Official Website www.daomaker.com/
Protocol Twitter/X @TheDaoMaker

How it happened

  1. According to DAO Maker, compromised administrative wallets allowed the attacker to create unauthorized SHO allocations.
  2. BlockSec traced a role-grant sequence from a wallet creator to an administrator, then to a contract given the DAO contracts role.
  3. That contract called withdrawFromUser to remove depositors' USDC.
  4. DAO Maker changed the signing arrangements and stopped further withdrawals.

Security review history

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.