Legacy MakerDAO auction keeper contract exploited; 200 ETH siphoned

AI مارکیٹ کا خلاصہ
CertiK reports an exploit of a legacy MakerDAO auction keeper contract that enabled withdrawal of 200 ETH, with funds laundered via Tornado Cash. While the contract is no longer part of the current Sky ecosystem, the incident highlights residual smart-contract risk from deprecated infrastructure and the possibility that other outdated contracts still holding funds remain vulnerable. Near-term impact is likely heightened caution toward DeFi protocol security and ETH-linked DeFi exposures.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
ETH/USDT-2.10%
AI تجزیاتی سمجھ · ETH/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
Odaily Planet Daily reported that blockchain security firm CertiK has identified an exploit involving a legacy MakerDAO auction keeper contract, enabling an attacker to withdraw 200 ETH. CertiK estimated the haul at more than $5 million. According to CertiK's analysis, the issue stemmed from missing access controls in the 0x8804d1de function within the keeper implementation contract. The contract dates back to the March 2020 "Black Thursday" liquidation event, when it acquired ETH with zero bids; four lots of 50 ETH each were left unsettled. The attacker is said to have taken those funds and laundered the proceeds through Tornado Cash, withdrawing in 10 ETH increments per transaction. While the contract is no longer part of the current Sky ecosystem, CertiK warned that other outdated contracts holding residual funds could remain exposed.