DIMO Hack

Reported loss $40K
Ethereum
Compromised privileged deployer key

What happened

On November 7, 2025, DIMO reported that a compromised developer/deployer key was used against an isolated Ethereum bridge proxy. The privileged signer upgraded the proxy and then invoked an emergency-withdrawal path that transferred 29,999,307.76 DIMO to an external address. Reporting described about $40,000 in sale proceeds, while estimates of the extracted token value vary; DIMO said its core network, token, and user assets were not affected.

Technical root cause

A bridge proxy concentrated upgrade and emergency-withdraw authority in a deployer-controlled privilege. Once that credential was compromised, the attacker could execute authorized administrative calls rather than bypassing a contract permission check. Moving ownership to a Safe multisig reduced that single-key custody risk.

How it happened

  1. The compromised deployer wallet first upgraded the ERC-1967 bridge proxy.
  2. The same privileged signer then invoked its emergency-withdrawal path, transferring 29,999,307.76362104 DIMO to an external recipient.
  3. DIMO’s response subsequently restored the proxy and transferred ownership from the deployer wallet to a Safe multisig.
  4. The public evidence establishes the privileged sequence, but not the initial off-chain compromise method or the identity of the recipient.

Protocol details

Classification Protocol Logic / Other / Key Compromise
Protocol Type Exploit/Access control
Category Bridge Hack
Protocol links Website @DIMO_Network

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.