Security· ★★★· bearish·

Hacker steals 200 ETH from legacy MakerDAO contract via 2020 vulnerability

  • —The 0x8804d1de function lacked access control, granting full control over the keeper's MakerDAO Vat account
  • —The hacker settled four old auctions, #1457-1460, each a 50 ETH lot won at zero bid in March 2020 but never paid
  • —All 200 ETH were withdrawn in a single transaction; deposits of 10 ETH into Tornado Cash started six minutes later
  • —Only the legacy contract was affected; current MakerDAO protocol contracts were not impacted
Why it matters: The incident shows that forgotten contracts and unsettled positions from past years remain a live risk for DeFi.
Source: Incrypted