Tapioca DAO Hack

REPORTED LOSS $4.7M
Medium Social-engineering private-key compromise used to mint USDO and extract TAP vesting tokens Arbitrum One

What happened

Tapioca DAO lost approximately $4.7 million on Arbitrum after a core contributor's private key was compromised through a social-engineering malware attack. The key controlled privileged TAP and USDO administration as a single-signer hot wallet, enabling unauthorized minting and token extraction.

Technical Root Cause

A privileged administrative key was stored and used as a single-signer hot wallet despite an intended multisig design. Its compromise gave the attacker direct authority over sensitive minting and rescue functions. The incident was a key-compromise and operational-control failure, not a discovered smart-contract logic flaw.

Case & protocol details

Classification Access control / compromised privileged key
Protocol Type Exploit/Access control
Implementation language Solidity
Official Website www.tapioca.xyz/
Protocol Twitter/X @tapioca_dao

How it happened

Using the compromised administrative key, the attacker added an unauthorized USDO minter and minted 315.5 trillion USDO, then exchanged it to drain about $3.1 million USDC from the USDO/USDC pool. The attacker also used a vesting-contract rescue function to take TAP tokens and sold them for ETH.

Tapioca removed liquidity from affected pools, reported roughly $700,000 protected, and later reported recovery of about $2.65 million in ETH collateral through a counter-exploit. The remaining gross loss was not fully recovered.

Funds Recovery

56.4%

Recovered

$2.6M

Net Loss

$2,049,200

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.