Legacy MakerDAO auction keeper contract exploited; 200 ETH siphoned

AI Market Summary
CertiK reports an exploit of a legacy MakerDAO auction keeper contract that enabled withdrawal of 200 ETH, with funds laundered via Tornado Cash. While the contract is no longer part of the current Sky ecosystem, the incident highlights residual smart-contract risk from deprecated infrastructure and the possibility that other outdated contracts still holding funds remain vulnerable. Near-term impact is likely heightened caution toward DeFi protocol security and ETH-linked DeFi exposures.
Impact level
● Medium
Affected assets
ETH/USDT-2.21%
AI Insight · ETH/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Odaily Planet Daily reported that blockchain security firm CertiK has identified an exploit involving a legacy MakerDAO auction keeper contract, enabling an attacker to withdraw 200 ETH. CertiK estimated the haul at more than $5 million. According to CertiK's analysis, the issue stemmed from missing access controls in the 0x8804d1de function within the keeper implementation contract. The contract dates back to the March 2020 "Black Thursday" liquidation event, when it acquired ETH with zero bids; four lots of 50 ETH each were left unsettled. The attacker is said to have taken those funds and laundered the proceeds through Tornado Cash, withdrawing in 10 ETH increments per transaction. While the contract is no longer part of the current Sky ecosystem, CertiK warned that other outdated contracts holding residual funds could remain exposed.