YZY DAO Hack
What happened
The contract deployer transferred ownership of the vault smart contract to the external address:
https://etherscan.io/tx/0x5742ab0e…a089cb
The new owner was set as _daoTreasury in the vault smart contract:
https://etherscan.io/address/0x0a5a0a14…49d4fe#readContract
The external wallet received tokens in the form of fees. In addition, he sold them in multiple transactions:
https://etherscan.io/txsInternal?a=0xf01a9074…585302&p=1
This address removed liquidity multiple times:
https://etherscan.io/tx/0x6d64293c…e7f9c9
https://etherscan.io/tx/0x59f3ae38…0c319d
https://etherscan.io/tx/0xe481e83b…4951c0
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report yzy.finance
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.