Dego Finance Hack
What happened
In February 2022, an attacker compromised credentials controlling Dego Finance's team-held liquidity and minting infrastructure. The attacker removed DEGO/ETH and DEGO/BNB liquidity from Uniswap and PancakeSwap and minted additional DEGO, with activity reported across BSC, Ethereum, and Cronos. Reported dollar-loss estimates vary with asset valuation and whether related COCOS-BCX wallets are included.
Private-key or privileged-wallet compromise; the exact initial compromise path was not publicly disclosed. Accounts able to manage liquidity or mint supply need multisig control, hardware-backed signing, separated duties, and operational limits.
How it happened
Dego attributed the incident to compromised team-controlled addresses, not a permissionless public smart-contract exploit. With that privileged access, the attacker withdrew team-provided LP liquidity and used the minting contract to create additional DEGO before moving and mixing assets. The team reported contacting exchanges and security firms while tracing the addresses.
Public evidence does not establish a verified dollar amount recovered, and it does not establish a rug pull or deliberate insider action.
Protocol details
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.