DIMO Hack
What happened
On November 7, 2025, DIMO reported that a compromised developer/deployer key was used against an isolated Ethereum bridge proxy. The privileged signer upgraded the proxy and then invoked an emergency-withdrawal path that transferred 29,999,307.76 DIMO to an external address. Reporting described about $40,000 in sale proceeds, while estimates of the extracted token value vary; DIMO said its core network, token, and user assets were not affected.
A bridge proxy concentrated upgrade and emergency-withdraw authority in a deployer-controlled privilege. Once that credential was compromised, the attacker could execute authorized administrative calls rather than bypassing a contract permission check. Moving ownership to a Safe multisig reduced that single-key custody risk.
How it happened
- The compromised deployer wallet first upgraded the ERC-1967 bridge proxy.
- The same privileged signer then invoked its emergency-withdrawal path, transferring 29,999,307.76362104 DIMO to an external recipient.
- DIMO’s response subsequently restored the proxy and transferred ownership from the deployer wallet to a Safe multisig.
- The public evidence establishes the privileged sequence, but not the initial off-chain compromise method or the identity of the recipient.
Protocol details
Evidence
- report @DIMO_Network incident report x.com
- report @CertiKAlert incident report x.com
- report @DIMO_Network incident report x.com
- report Nominis November 2025 incident report nominis.io
- transaction DIMO emergency-withdraw transaction etherscan.io
- address DIMO bridge proxy etherscan.io
- analysis DeFiLlama defillama.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.