DAO Maker Vesting Hack
What happened
On 3-4 September 2021 an attacker drained DAO Maker's vesting contracts on Ethereum, taking about $4 million in vested public-sale tokens of four projects: DeRace (DERC), Showcase (SHO), Ternoa (CAPS) and CoinsPaid (CPD). The vesting contracts' init() function did not check the caller, so the attacker re-initialized four contracts with their own parameters, made themselves owner, and then called emergencyExit() to pull the tokens out.
The attacker, 0x2708cace7b42302af26f1ab896111d87faeff92f, withdrew tokens in these emergencyExit() transactions:
0xcb5be97496995d58da6f97491845040547b878e53a7b71f907a13408f3a54e5f(about 13.5M CAPS)0x4c273c2403aafd97e4b553f0e381cf1c63e5f2efebbe2ded7642a06f2b68c8790x1692a57f19b5e8e4bc6a372ac3c83c77cd4a1ea78414377ea66d3d59f4a7d2b70xdd0176475165b83c702d49a876d4dc888b73477ad8833582c72aa6ca5e0bacc3(about 20.6M SHO)
The tokens were then sold for DAI through DEX aggregators in these transactions:
0xbf38346aacf261f5e169a87ed874c33c21efb060c4a393e2b1443a3ac5d6e3fd0x3436af2c84d67254a4b81adc350c91d1b98ae52b2ff84645d14d4245c2d08c270xc586a6b94e09556abf46ae3aa8cffa8e46dfcb0c22bce0b024d5e01743ceba9e0x76163daf6cf0c815c02fb1a98f5c6283ee7a922cbad41218eb7a6452c91824c8
The affected tokens fell sharply after the dumps. DAO Maker said it would stop running smart contracts that hold user or project assets and would buy tokens on the market so affected sale participants still received their tokens in later releases. Rekt reported that this was DAO Maker's second exploit in about a month.
How it happened
- DAO Maker's vesting contracts held locked public-sale tokens for DeRace, Showcase, Ternoa and CoinsPaid.
- The contracts'
init()function had no caller authentication, so anyone could call it again after deployment. - The attacker called
init()on four vesting contracts, overwriting their key parameters and setting themselves as owner in the same call. - As owner, the attacker called
emergencyExit(receiver)on each contract, sending the whole token balance to their own address. - The attacker sold the tokens for DAI through DEX aggregators, crashing the affected token prices.
Protocol details
Security review history
- Hacken View report
- PeckShield View report
- Zokyo View report
Evidence
Proof of concept
1 availableSources
- report Twitter/X Alert twitter.com
- report @Mudit__Gupta incident report twitter.com
- report Post-mortem medium.com
- report DAO Maker - REKT 2 rekt.news
- transaction Transaction etherscan.io
- transaction Etherscan transaction 0xcb5be974...a54e5f etherscan.io
- transaction Etherscan transaction 0xdd017647...bacc3 etherscan.io
- transaction etherscan.io transaction 0x1692…d2b7 etherscan.io
- transaction etherscan.io transaction 0x3436…8c27 etherscan.io
- transaction etherscan.io transaction 0x4c27…c879 etherscan.io
- transaction etherscan.io transaction 0x7616…24c8 etherscan.io
- transaction etherscan.io transaction 0xbf38…e3fd etherscan.io
- transaction etherscan.io transaction 0xc586…ba9e etherscan.io
- address etherscan.io address 0x2708…f92f etherscan.io
- analysis Website reference slowmist.medium.com
- analysis DeFiLlama defillama.com
- analysis Hacked: Blockchain Security Firm SlowMist Shares Analysis Of Recent DAO Maker Exploit crowdfundinsider.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.