Synthetify Hack
What happened
In October 2023 an attacker drained about $230,000 in USDC, mSOL and stSOL from the treasury of the Synthetify DAO on Solana by passing their own governance proposal. The DAO was largely inactive, so nobody voted against it.
The attacker created ten proposals that looked alike. Nine were empty; the tenth contained an instruction transferring treasury assets to the attacker's address. The attacker's own governance tokens were enough to reach quorum, and the proposal executed before other members noticed. Neodyme, which described the case, said the campaign ran for about three months and used spam proposals to test the waters and hide the backdoored one, in a DAO whose governance token was mispriced relative to its treasury.
The stolen funds were sent to Tornado Cash. Synthetify froze its programs and platform after the discovery, and no recovery has been reported. About $89,669 was reported as remaining in the treasury.
How it happened
- The attacker held enough of the DAO's governance tokens to meet the voting quorum on their own, in a DAO where few holders still voted.
- Over roughly three months they submitted proposals that looked like spam, testing whether anyone would react.
- They submitted ten similar proposals: nine empty, one carrying an instruction that sent USDC, mSOL and stSOL from the treasury to their address.
- They voted the proposals through with their own tokens and met no opposition.
- The malicious proposal executed, moving about $230,000 to the attacker, who then sent the funds to Tornado Cash.
Protocol details
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.