Dego Finance Hack

Reported loss $10.0M
BNB Chain Cronos Ethereum
Private Key Compromise

What happened

In February 2022, an attacker compromised credentials controlling Dego Finance's team-held liquidity and minting infrastructure. The attacker removed DEGO/ETH and DEGO/BNB liquidity from Uniswap and PancakeSwap and minted additional DEGO, with activity reported across BSC, Ethereum, and Cronos. Reported dollar-loss estimates vary with asset valuation and whether related COCOS-BCX wallets are included.

Technical root cause

Private-key or privileged-wallet compromise; the exact initial compromise path was not publicly disclosed. Accounts able to manage liquidity or mint supply need multisig control, hardware-backed signing, separated duties, and operational limits.

How it happened

Dego attributed the incident to compromised team-controlled addresses, not a permissionless public smart-contract exploit. With that privileged access, the attacker withdrew team-provided LP liquidity and used the minting contract to create additional DEGO before moving and mixing assets. The team reported contacting exchanges and security firms while tracing the addresses.

Public evidence does not establish a verified dollar amount recovered, and it does not establish a rug pull or deliberate insider action.

Protocol details

Classification Infrastructure / Access Control
Protocol Type Services
Affected asset / contract DEGO
Protocol links Website @dego_finance

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.