TempleDAO Hack
Incident Overview
TempleDAO's staking contract was exploited due to a vulnerable migration functionality. The hacker took away FraxLP tokens and swapped them for 1830 $ETH.
TempleDAO is a DeFi yield aggregator. The exploit happens due to stake migration functionality on the StaxLPStaking contract. The attacker was able to transfer xFraxTempleLP liquidity tokens to his address and took $TEMPLE and $FRAX tokens from the pool.
Consequently, the hacker swapped them for 1830 $ETH and transferred the stolen funds to another EOA address. The total profit of the attacker reached 2,376,872 $USD. An interesting detail is that the attacker's address was linked to Binance's address.
TempleDAO is investigating the accident with Binance and Stax said that a white hat bounty will be initialized for the exploiter.
Attacker address:
https://etherscan.io/address/0x9c9Fb310…D25B01
Malicious transaction:
https://etherscan.io/tx/0x8c3f442f…cf04b5
Liquidity removal transaction:
https://etherscan.io/tx/0x4b119a4f…ddb6a2
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to TempleDAO, these are the critical security checks that could have prevented this incident (October 2022).
- Verify all logic paths related to Exploit Lack of Input Authentication / Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialPost-Incident Timeline
-
2022-10-17
On 16 October 2022, the stolen amount of 1831 $ETH was moved into TornadoCash from the EOA address https://etherscan.io/address/0x2b63d4a3b2db8acbb2671ea7b16993077f1db5a0
Proof-of-Concept Exploits
On-Chain Evidence & References
- Twitter/X Alert https://twitter.com/BlockSecTeam/status/1579843881893769222
- Block Explorer https://etherscan.io/tx/0x8c3f442fc6d640a6ff3ea0b12be64f1d4609ea…
Sources & References
Learn to Prevent the Next TempleDAO
The TempleDAO hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.