200 WETH withdrawn from dormant third-party MakerDAO liquidation bot proxy

200 WETH withdrawn from dormant third-party MakerDAO liquidation bot proxy

N
News Editor
2026-10-06 08:57:57
Defimon Alerts said a newly funded address linked to Tornado Cash withdrew 200 WETH from a dormant MakerDAO ETH-A liquidation bot proxy on Oct. 6, in an incident valued at about $538,000. The proxy had previously won four ETH-A liquidation auctions in 2020, auctions No. 1457 through 1460, with 50 WETH tied to each one, but never called deal(), leaving the collateral sitting in Flipper. The issue was not described as a failure in MakerDAO’s core contracts. Instead, the problem came from the implementation contract behind a third-party keeper bot. Its withdrawal function was not protected by ds-auth, which meant any caller could trigger the sequence. According to the description, the caller could first execute deal() on the old auctions, then move the collateral to the keeper through Vat.flux, and finally use GemJoin.exit to send the 200 WETH to an address of their choice and unwrap it into ETH. The case points to a permissions failure in external keeper infrastructure rather than a flaw in MakerDAO’s core system design.

Defimon Alerts reported that a newly funded address linked to Tornado Cash withdrew 200 WETH from a dormant MakerDAO ETH-A liquidation bot proxy on Oct. 6, with losses estimated at about $538,000.

Old auction collateral was still sitting in Flipper

The upgradable proxy had won four ETH-A liquidation auctions in 2020, auction numbers 1457 through 1460, with 50 WETH in each auction. But it never called deal(), which left the collateral in Flipper.

An unprotected withdrawal function allowed anyone to trigger the flow

According to the disclosed execution path, the implementation contract’s withdrawal function was not protected by ds-auth. That meant any caller could activate the process: first call deal() on the old auctions, then move the collateral to the keeper through Vat.flux, and finally use GemJoin.exit to transfer the 200 WETH to an address specified by the caller and unwrap it into ETH.

The flaw was in a third-party bot, not MakerDAO core contracts

The report said MakerDAO’s core contracts operated as designed. The weakness was in the third-party liquidation bot’s exit function, which lacked access control.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.