Tapioca DAO Hack
What happened
Tapioca DAO lost approximately $4.7 million on Arbitrum after a core contributor's private key was compromised through a social-engineering malware attack. The key controlled privileged TAP and USDO administration as a single-signer hot wallet, enabling unauthorized minting and token extraction.
A privileged administrative key was stored and used as a single-signer hot wallet despite an intended multisig design. Its compromise gave the attacker direct authority over sensitive minting and rescue functions. The incident was a key-compromise and operational-control failure, not a discovered smart-contract logic flaw.
Case & protocol details
How it happened
Using the compromised administrative key, the attacker added an unauthorized USDO minter and minted 315.5 trillion USDO, then exchanged it to drain about $3.1 million USDC from the USDO/USDC pool. The attacker also used a vesting-contract rescue function to take TAP tokens and sold them for ETH.
Tapioca removed liquidity from affected pools, reported roughly $700,000 protected, and later reported recovery of about $2.65 million in ETH collateral through a counter-exploit. The remaining gross loss was not fully recovered.
Funds Recovery
Recovered
$2.6M
Net Loss
$2,049,200
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.