Skip to content
Est. MMXXVIVol. VI · № 349RSS
Blockchain Breaches

An archive of cryptocurrency security incidents — hacks, exploits, bridge failures and rug pulls, documented with on-chain evidence.

Dossier № 348Smart Contract Bug

MakerDAO Legacy Keeper Bot Drain

A dormant MakerDAO ETH-A liquidation keeper lost 200 WETH (about $538,000) when an attacker exploited an unprotected withdrawal function to drain collateral stranded since Black Thursday 2020.

Date
Chain(s)
Status
Funds Stolen
Attribution
0x01EB957e5C7DcDDD60F3C875956cCc6fB9bDa5FA

On October 6, 2026, a dormant MakerDAO ETH-A liquidation keeper — a third-party bot, not MakerDAO's core protocol — was drained of 200 WETH, worth approximately $538,000, after an attacker exploited an unprotected withdrawal function in the keeper's implementation contract. The stolen collateral had sat untouched on-chain since the "Black Thursday" liquidations of March 2020.

What happened

CertiK traced the loss to keeper implementation 0x68399ed8aa33C5b43F863EE6782de492006A5546, where function selector 0x8804d1de lacked the ds-auth check that guarded the contract's other privileged functions. The function accepted any address as an adapter, called Vat.hope to delegate authority to it, and invoked its join() — never calling nope afterward, so the delegation persisted. During Black Thursday in March 2020, this keeper had won four 50-ETH ETH-A auctions (IDs 1457–1460) with zero bids and never settled them, leaving 200 ETH locked in the retired ETH-A Flipper (0xd8a04F5412223F513DC55F839574430f5EC15531). Because anyone can call deal on a completed auction, the attacker settled those six-year-old auctions, credited the 200 ETH to the keeper's Vat account, and exited it through the ETH-A GemJoin as 200 WETH to an attacker-controlled contract. MakerDAO's core contracts (Vat, Flipper, GemJoin) behaved exactly as designed; the flaw lived entirely in the forgotten keeper.

Aftermath

The attacker had funded a fresh address with a 0.1 ETH withdrawal from Tornado Cash at 05:57 UTC, roughly 16 minutes before the exploit landed in block 26,131,471 at 06:13 UTC. About six minutes after the drain, the proceeds were pushed back into Tornado Cash in 10-ETH batches, leaving no realistic recovery path. No MakerDAO team response, bounty, or clawback was announced, and the funds remain stolen. On-chain investigators flagged the attacker address as 0x01EB957e5C7DcDDD60F3C875956cCc6fB9bDa5FA.

Why it matters

The incident is a textbook reminder that abandoned contracts never stop being attack surface. The same lesson runs through the Thetanuts Finance deprecated-vault exploit and the 1inch resolver legacy Fusion v1 bug: sunsetting a product does not remove its code — or its funds — from the chain. It also shows how a single missing ds-auth modifier, trivial in isolation, becomes catastrophic once it guards real value. Here that value had been quietly stranded for more than six years, a remnant of one of DeFi's most chaotic days, until an opportunist with a Tornado Cash deposit and a careful reading of old auction state finally collected it.

Sources & on-chain evidence

  1. [01]certik.comhttps://www.certik.com/blog/makerdao-legacy-auction-keeper-incident-analysis
  2. [02]cryptotimes.iohttps://www.cryptotimes.io/2026/10/06/dormant-makerdao-keeper-drained-of-538k-core-remains-intact/
  3. [03]kucoin.comhttps://www.kucoin.com/news/flash/certik-reports-keeper-bot-exploit-in-makerdao-liquidation-system
  4. [04]chaincatcher.comhttps://www.chaincatcher.com/en/article/2294394

Related filings