TempleDAO Hack

TOTAL LOST $2.4M
Medium Access Control Attacks ethereum

What happened

TempleDAO's staking contract was exploited due to a vulnerable migration functionality. The hacker took away FraxLP tokens and swapped them for 1830 $ETH.

TempleDAO is a DeFi yield aggregator. The exploit happens due to stake migration functionality on the StaxLPStaking contract. The attacker was able to transfer xFraxTempleLP liquidity tokens to his address and took $TEMPLE and $FRAX tokens from the pool.

Consequently, the hacker swapped them for 1830 $ETH and transferred the stolen funds to another EOA address. The total profit of the attacker reached 2,376,872 $USD. An interesting detail is that the attacker's address was linked to Binance's address.

TempleDAO is investigating the accident with Binance and Stax said that a white hat bounty will be initialized for the exploiter.

Attacker address:

https://etherscan.io/address/0x9c9Fb310…D25B01

Malicious transaction:

https://etherscan.io/tx/0x8c3f442f…cf04b5

Liquidity removal transaction:

https://etherscan.io/tx/0x4b119a4f…ddb6a2

Case & protocol details

Classification Protocol Logic / Yield Aggregator / Access Control
Protocol Type Reserve Currency
Affected asset / contract TEMPLE
Smart Contract Language Solidity
Official Website templedao.link/
Protocol Twitter/X @templedao

Post-Incident Timeline

  • 2022-10-17

    On 16 October 2022, the stolen amount of 1831 $ETH was moved into TornadoCash from the EOA address https://etherscan.io/address/0x2b63d4a3b2db8acbb2671ea7b16993077f1db5a0

Evidence & learning

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.