Skip to content
Basis Desk

New: Basis Desk Verify for Chrome — fact-check crypto news on any page, free.Add to Chrome →

Security & Hacks · 1 min read

Attacker Drains 200 ETH From Dormant MakerDAO Auction Keeper

A legacy keeper contract lost $542,982 in ETH-A collateral after an unauthenticated function let an attacker settle and claim unsettled 2020 auction lots.

Editorial oversight: Julian Mercer, Chief Editor
Bearish

At a glance

What happened
An attacker exploited an unauthenticated function in a legacy MakerDAO auction-keeper contract to drain 200 ETH on Oct. 6.
Why it matters
The incident reveals that unsettled assets from historical liquidations in unmaintained proxy contracts remain vulnerable to extraction.
Who is affected
The private owner and operator of the legacy auction-keeper contract.
What's next
No next step announced.
Primary source
certik.com: MakerDAO Legacy Auction Keeper Incident Analysis

Key points

  • An attacker drained 200 ETH ($542,982) from a legacy MakerDAO auction-keeper contract on Oct. 6 1.
  • The keeper possessed unsettled lots won with zero bids during MakerDAO's March 2020 Black Thursday crash 1.
  • Missing access control allowed the attacker to gain full delegation over the keeper's Vat balance and route proceeds to Tornado Cash 1.

An attacker drained 200 $ETH ($542,982 at the time of the incident) from an unmaintained MakerDAO auction-keeper contract on Ethereum mainnet on Oct. 6, according to an analysis by blockchain security firm CertiK 1. The stolen assets stemmed from four 50 ETH lots won with zero bids during MakerDAO's "Black Thursday" liquidations in March 2020 that were left unsettled 1.

CertiK reported that the breach exploited an access control omission in keeper implementation 0x68399ed8aa33C5b43F863EE6782de492006A5546 1. While other sensitive functions required authorization checks, an unauthenticated method allowed any caller to register an arbitrary adapter module 1. Upon invocation, the keeper executed Vat.hope(), giving the malicious module complete authority over the keeper's internal balance in MakerDAO's core accounting contract before invoking an execution callback 1.

Unsettled Collateral and Fund Movement

Inside the callback, the attacker's module initiated settlement on the retired ETH-A Flipper contract for auctions 1457 through 1460 1. Because any entity can settle finalized auctions, the contract credited 200 ETH of ETH-A collateral to the keeper's internal balance, which the attacker immediately transferred away using the freshly granted delegation 1. The attacker then exited the position through the ETH-A GemJoin contract and forwarded the funds as wrapped ether 1.

Blockchain records show the operation was funded through an initial 0.1 ETH withdrawal from Tornado Cash minutes before the attack 1. Six minutes after the exploit transaction confirmed, the perpetrator began laundering the stolen capital through the privacy mixer in 10 ETH increments 1. MakerDAO governance systems were not directly modified during the incident, as the vulnerability resided entirely within a third-party legacy keeper proxy rather than MakerDAO's active core contracts 1. At the time of writing, MakerDAO's governance token $MKR traded at $1,844, down 7.9% over the past 24 hours.

Sources

  1. [1] MakerDAO Legacy Auction Keeper Incident Analysis — certik.com, October 7, 2026

Written by Basis Desk's newsroom system from the primary sources above and machine-verified against them before publication. Market figures marked "at the time of writing" come from live exchange data. Report an error: corrections@basisdesk.news · corrections policy.

Community read
How do you read this story for the assets involved? One vote a day, anonymous.
Be the first to vote

The Daily Brief, in your inbox at 07:00 ET

Five stories, the numbers that moved, what to watch. Three minutes. No hype, no advice, unsubscribe in one click.

Not financial advice. Basis Desk publishes information, not recommendations. Crypto assets are volatile and you can lose what you invest.