Security firm CertiK said a legacy MakerDAO auction keeper contract was exploited, allowing an attacker to withdraw 200 ETH worth more than $500,000. According to CertiK, the issue came from missing access control on function 0x8804d1de in the keeper implementation contract. The contract had previously taken part in the March 2020 “Black Thursday” liquidation crisis, when it won ETH with zero bids. Four lots of 50 ETH each were never settled, and the attacker later removed those funds. CertiK said the ETH was then moved out through Tornado Cash in 10 ETH increments per transaction. The firm added that the contract is not a core part of the current Sky ecosystem, but older contracts that still hold funds may remain exposed to similar attacks.
Security firm CertiK said a legacy MakerDAO auction keeper contract was exploited, with an attacker withdrawing 200 ETH worth more than $500,000.
CertiK said the root cause was missing access control on function 0x8804d1de in the keeper implementation contract. The contract had previously participated in the March 2020 “Black Thursday” liquidation crisis, when it won ETH with zero bids. Four lots of 50 ETH each were never settled. The attacker was able to take those funds and then move them out through Tornado Cash in 10 ETH increments per transaction.
CertiK added that the contract is not a core part of the current Sky ecosystem, but older contracts that still still hold funds may remain potential targets.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.