DAO Maker SHO Hack (August 2021)
What happened
DAO Maker's August 2021 incident drained approximately $7 million in USDC from its Strong Holder Offering (SHO) deposit system. The CEO said two administrative multisignature wallets were compromised. DAO Maker said its vault and vesting contracts were unaffected.
Administrative authority was used to grant withdrawal permissions in the SHO/Essential contract system. The on-chain role grants explain the withdrawals, but do not establish how the administrative wallets were initially compromised.
Case & protocol details
How it happened
- According to DAO Maker, compromised administrative wallets allowed the attacker to create unauthorized SHO allocations.
- BlockSec traced a role-grant sequence from a wallet creator to an administrator, then to a contract given the DAO contracts role.
- That contract called withdrawFromUser to remove depositors' USDC.
- DAO Maker changed the signing arrangements and stopped further withdrawals.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.