{"investigation":{"slug":"badger-dao","entity_name":"Badger DAO","trust_score":10,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"Badger DAO is a decentralized autonomous organization and DeFi protocol launched in December 2020 focused on generating yield on Bitcoin-backed assets via Ethereum-based vaults. In December 2021, a front-end attack exploiting a compromised Cloudflare API key resulted in approximately $120–130 million in user funds being drained across roughly 500 wallets. As of 2025, the protocol has seen significant decline: its flagship eBTC product was sunset, BADGER was delisted from Binance, and total value locked has fallen to low single-digit millions.","sections":[{"content":"Badger DAO was founded in September 2020 by Chris Spadafora, Ameer Rosic, Albert Castellana, and Alberto Cevallos. The protocol launched publicly in December 2020 with a stated mission to accelerate Bitcoin's use across DeFi. Its core product, Sett Vaults, allowed users to deposit synthetic Bitcoin tokens such as WBTC and renBTC in exchange for yield-bearing positions. A second product, DIGG, introduced an elastic-supply token pegged to the price of Bitcoin. The native governance token, BADGER, was modeled with a fixed maximum supply of 21 million tokens mirroring Bitcoin's supply cap. The project launched without a pre-sale or venture capital funding, using a fair-distribution model. At its peak in late 2021, Badger DAO held over $1 billion in total value locked.","heading":"Background","sources":[{"url":"https://badgerdao.medium.com/introducing-badger-dao-ed47a586c619","name":"","type":"other","credibility":3},{"url":"https://www.kraken.com/learn/what-is-badger-dao","name":"","type":"other","credibility":3},{"url":"https://iq.wiki/wiki/badgerdao","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On December 2, 2021, BadgerDAO suffered one of the largest DeFi exploits in history — a front-end attack that drained approximately $120–130 million from user wallets. Unlike most DeFi exploits, the attack did not target smart contract vulnerabilities. Instead, it exploited BadgerDAO's web infrastructure through a compromised Cloudflare API key.\n\nAccording to Badger's post-incident disclosure, three accounts had been created and granted Cloudflare API keys without authorization in August and September 2021. A critical flaw in Cloudflare's account management system at the time allowed users to create accounts and view global API keys without completing email verification. In mid-September 2021, Badger unknowingly completed the account creation for one of these pre-seeded compromised accounts; the Cloudflare UI did not surface a warning that the account had already been created and an API key generated.\n\nBeginning November 10, 2021, the attacker used the unauthorized API key to inject malicious JavaScript via Cloudflare Workers into specific routes of the Badger web application. The script was deployed intermittently across November to evade detection — applied and removed periodically, often for short windows. Anti-detection measures included targeting only wallets above a certain balance, explicitly avoiding wallets belonging to Badger's own developer multisig signers, accessing the API from multiple proxy and VPN IP addresses, and modifying the script on each deployment so that each version had a unique hash, rendering static signature detection ineffective.\n\nThe malicious script intercepted Web3 transaction requests as users interacted with the protocol. When triggered, it appended additional ERC-20 token spend approvals to the attacker's address, granting unlimited token transfer rights from victim wallets. On November 20, 2021, the attacker obtained the first successful rogue approval. The attacker then waited, accumulating approvals across approximately 500 wallets before executing the bulk withdrawal.\n\nOn December 1, 2021, a single wallet — alleged by blockchain researchers to be associated with Celsius Network — approved the attacker's access to 896 Wrapped Bitcoin (approximately $50 million at the time). The attacker immediately drained that position, then swept all other accumulated approvals in rapid succession. PeckShield estimated total outflows of approximately 2,100 BTC and 151 ETH. Badger engineers halted the attack by exercising an emergency pause on all smart contract calls to the transferFrom function, preventing further theft. Approximately $9 million in assets transferred by the attacker but not yet withdrawn from Badger's vaults was identified as potentially recoverable.","heading":"The Frontend Attack","sources":[{"url":"https://www.coindesk.com/business/2021/12/10/badgerdao-reveals-details-of-how-it-was-hacked-for-120m","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-badgerdao-hack-december-2021","name":"","type":"other","credibility":3},{"url":"https://zengo.com/the-badgerdao-hack-what-really-happened-and-why-it-matters/","name":"","type":"other","credibility":3},{"url":"https://www.bloomberg.com/news/articles/2021-12-10/badgerdao-says-cloudflare-flaw-led-to-130-million-heist","name":"","type":"other","credibility":3},{"url":"https://www.theblock.co/post/126072/defi-protocol-badgerdao-exploited-for-120-million-in-front-end-attack","name":"","type":"other","credibility":3},{"url":"https://beincrypto.com/badgerdao-post-mortem-details-fourth-largest-defi-exploit/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Blockchain security firm PeckShield performed on-chain analysis in the immediate aftermath of the exploit and estimated total outflows of approximately 2,100 BTC and 151 ETH from BadgerDAO vaults, valuing the theft at roughly $120 million at prevailing prices. The largest single victim address lost 896 Wrapped Bitcoin, worth approximately $50–51 million. On-chain researchers identified this address as likely belonging to Celsius Network based on its interaction history with other addresses publicly tagged as Celsius Network wallets on Etherscan; Celsius subsequently confirmed losses in the hack. Celsius later acknowledged approximately $50–55 million in wBTC losses, a figure that became significant context during Celsius's own bankruptcy proceedings in 2022.\n\nBadger engaged blockchain analytics firm Chainalysis to trace the flow of stolen funds using its Reactor tool. Chainalysis confirmed it was actively assisting in tracking the attacker's wallet activity. The approximately $9 million in tokens that the attacker had transferred into Badger's own vaults but had not yet withdrawn represented a recoverable tranche, as those funds were still addressable via a governance-authorized contract upgrade. Forta Network, an on-chain threat detection platform, later published an analysis noting that bot-detected anomalies in the approval patterns during November 2021 could have provided an early warning signal, had monitoring been in place.\n\nChainalysis also engaged in public discussion of the case via its podcast, describing it as a notable example of a non-smart-contract DeFi attack with significant on-chain traceability.","heading":"On-Chain Evidence","sources":[{"url":"https://blockworks.co/news/hackers-drain-115-million-from-bitcoin-defi-focused-badgerdao","name":"","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2021/12/03/crypto-lender-celsius-admits-losses-in-120m-badgerdao-hack","name":"","type":"other","credibility":3},{"url":"https://cryptopotato.com/celsius-network-reportedly-lost-50-million-in-the-120-million-badgerdao-hack/","name":"","type":"other","credibility":3},{"url":"https://www.chainalysis.com/blog/chainalysis-podcast-episode-6-badgerdao-hack/","name":"","type":"other","credibility":3},{"url":"https://forta.org/blog/how-to-derail-a-120-million-dollar-hack/","name":"","type":"other","credibility":3},{"url":"https://dailycoin.com/single-user-loses-50-million-bitcoin-in-badger-dao-hack/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, Badger paused all smart contract activity and disclosed the cause of the breach on December 10, 2021. The team patched the Cloudflare configuration, rotated all API keys, and hired cybersecurity firm Mandiant and blockchain analytics firm Chainalysis to assist in the investigation. Badger also stated it was cooperating with law enforcement authorities in the United States and Canada in efforts to identify and recover funds.\n\nGovernance proposals BIP-76, BIP-77, and BIP-78 were introduced to authorize a one-time contract upgrade enabling the protocol to seize approximately $9.2 million in attacker-held vault tokens and return them to affected users. The proposals passed with substantial majority votes. This mechanism allowed a subset of affected users — approximately 38% — to receive token-for-token restitution from the seized funds.\n\nFor the remaining losses, BadgerDAO proposed a tiered compensation framework dividing affected assets into three tranches governed by separate DAO processes. The community acknowledged that full immediate restitution was not feasible, with the plan involving a combination of direct payouts and a longer-term vault-based repayment mechanism. Governance deliberations over the restitution plan drew scrutiny from observers as a test of DAO governance capabilities under crisis conditions.\n\nCelsius Network, the largest single alleged victim, later filed for bankruptcy in July 2022. A subsequent investigation revealed that an error in Celsius's claims process during the BadgerDAO restitution resulted in Celsius forfeiting approximately $22 million in recovery entitlements due to administrative failures on Celsius's part, according to reporting by Dirty Bubble Media.\n\nAs of available reporting, no suspect has been publicly arrested or charged in connection with the exploit. The attacker's identity remains unknown.","heading":"Recovery Efforts","sources":[{"url":"https://www.coindesk.com/tech/2021/12/16/after-130m-hack-badgers-restitution-plan-tests-limits-of-dao-governance","name":"","type":"other","credibility":3},{"url":"https://ambcrypto.com/badgerdao-reveals-cause-behind-exploit-details-recovery-plan/","name":"","type":"other","credibility":3},{"url":"https://forum.badger.finance/t/bip-77-reactivate-smart-contracts-and-recover-funds/5178","name":"","type":"other","credibility":3},{"url":"https://www.dirtybubblemedia.com/p/an-inexplicable-error-cost-celsius","name":"","type":"other","credibility":3},{"url":"https://www.hoptrail.io/post/badgerdao-exploit-illustrating-celsius-poor-controls","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Badger DAO's risk profile is evaluated as critical. The protocol experienced one of the most significant DeFi exploits to date, losing approximately $120–130 million in user funds through a web2 infrastructure compromise rather than a smart contract vulnerability — a vector that is comparatively rare and demonstrated that DeFi protocols face substantial risk from their centralized web infrastructure dependencies, including CDN providers such as Cloudflare.\n\nThe attacker operated undetected for approximately three weeks, exploiting Cloudflare account management weaknesses and employing sophisticated anti-detection techniques. The exploit affected approximately 500 user wallets and demonstrated that unlimited ERC-20 token approvals represent a persistent risk vector when front-end code is untrusted.\n\nPost-exploit recovery was partial. Full restitution was not achieved; a meaningful fraction of affected users received compensation through the seized vault funds governance mechanism, but the majority of losses remain unrecovered. The protocol relaunched but has seen sustained decline. TVL fell to approximately $9–10 million by 2023, a fraction of its pre-hack levels. The BADGER token lost approximately 85.6% of its value during 2022. The eBTC protocol, BadgerDAO's next major product, was sunset by the Treasury Council in June 2025 after failing to achieve product-market fit. Binance delisted BADGER on April 16, 2025 following a community vote; Crypto.com followed on June 17, 2025; OKX announced delisting of BADGER perpetual contracts effective July 25, 2025.\n\nThese factors collectively indicate a protocol in advanced decline with no clear recovery path. Users considering any interaction with Badger DAO vaults or BADGER token should be aware of extremely low liquidity, limited active development, and the historical precedent of catastrophic user fund loss. The hack has also been widely cited as a canonical example of front-end attack risk in DeFi security literature.","heading":"Risk Assessment","sources":[{"url":"https://defillama.com/protocol/badger-dao","name":"","type":"other","credibility":3},{"url":"https://www.tradingview.com/news/coindar:c3b007e7c094b:0-badger-dao-to-be-delisted-from-binance-on-april-16th/","name":"","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2025/04/09/binance-to-delist-14-tokens-after-community-vote/","name":"","type":"other","credibility":3},{"url":"https://coinmarketcap.com/cmc-ai/badger-dao/latest-updates/","name":"","type":"other","credibility":3},{"url":"https://redefine.net/media/badger-dao-attack/","name":"","type":"other","credibility":3},{"url":"https://www.microsoft.com/en-us/security/blog/2022/02/16/ice-phishing-on-the-blockchain/","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2020-09","event":"Badger DAO founded by Chris Spadafora, Ameer Rosic, Albert Castellana, and Alberto Cevallos.","source":"","date_original":"2020-09-01"},{"date":"2020-12","event":"Badger DAO publicly launches with BADGER token fair distribution and Sett Vaults product.","source":"","date_original":"2020-12-01"},{"date":"2021-08","event":"Alleged: Three unauthorized accounts created and granted Cloudflare API keys without authorization, exploiting a flaw in Cloudflare's email verification process.","source":"","date_original":"2021-08-01"},{"date":"2021-09-15","event":"Badger team unknowingly completes account creation for one of the pre-seeded compromised Cloudflare accounts.","source":""},{"date":"2021-11-10","event":"Attacker begins periodically injecting malicious JavaScript via Cloudflare Workers into BadgerDAO's web application routes.","source":""},{"date":"2021-11-20","event":"Attacker obtains the first successful unauthorized ERC-20 approval from a user wallet.","source":""},{"date":"2021-12","event":"Largest single victim — a wallet alleged to be associated with Celsius Network — approves attacker access to 896 Wrapped Bitcoin (~$50 million). Attacker begins mass withdrawal of funds across all accumulated approvals.","source":"","date_original":"2021-12-01"},{"date":"2021-12-02","event":"BadgerDAO detects the exploit and freezes all smart contract transferFrom calls, halting further theft. PeckShield estimates losses of approximately 2,100 BTC and 151 ETH (~$120 million).","source":""},{"date":"2021-12-03","event":"Celsius Network publicly confirms it suffered losses in the BadgerDAO exploit.","source":""},{"date":"2021-12-10","event":"BadgerDAO publishes post-incident disclosure attributing the breach to a compromised Cloudflare API key and maliciously injected script.","source":""},{"date":"2021-12-16","event":"Governance proposals BIP-76, BIP-77, and BIP-78 introduced to authorize seizure of ~$9.2 million in recoverable attacker-held vault tokens and begin restitution.","source":""},{"date":"2022","event":"Protocol relaunches after third-party audits of web2 and web3 infrastructure are completed.","source":"","date_original":"2022-01-01"},{"date":"2022-07","event":"Celsius Network files for bankruptcy. Subsequent reporting reveals Celsius forfeited ~$22 million in BadgerDAO restitution entitlements due to an administrative error in its claims process.","source":"","date_original":"2022-07-01"},{"date":"2025-04-16","event":"Binance delists BADGER following a community vote-to-delist, citing low trading volume and development activity.","source":""},{"date":"2025-06-11","event":"BadgerDAO Treasury Council announces sunset of the eBTC protocol, citing failure to achieve product-market fit and insufficient TVL to sustain revenue.","source":""},{"date":"2025-06-17","event":"Crypto.com delists BADGER token.","source":""},{"date":"2025-07-25","event":"OKX announces delisting of BADGER/USDT perpetual contracts.","source":""}],"sources_used":[{"url":"https://badgerdao.medium.com/introducing-badger-dao-ed47a586c619","name":"","type":"other","archive_url":"http://web.archive.org/web/20260113033224/https://badgerdao.medium.com/introducing-badger-dao-ed47a586c619","credibility":3,"archive_timestamp":"2026-01-13T03:32:24+00:00"},{"url":"https://www.kraken.com/learn/what-is-badger-dao","name":"","type":"other","archive_url":"http://web.archive.org/web/20260718201711/https://www.kraken.com/learn/what-is-badger-dao","credibility":3,"archive_timestamp":"2026-07-18T20:17:11+00:00"},{"url":"https://iq.wiki/wiki/badgerdao","name":"","type":"other","archive_url":"http://web.archive.org/web/20251214161913/https://iq.wiki/wiki/badgerdao","credibility":3,"archive_timestamp":"2025-12-14T16:19:13+00:00"},{"url":"https://www.coindesk.com/business/2021/12/10/badgerdao-reveals-details-of-how-it-was-hacked-for-120m","name":"","type":"other","archive_url":"http://web.archive.org/web/20260202000346/https://www.coindesk.com/business/2021/12/10/badgerdao-reveals-details-of-how-it-was-hacked-for-120m","credibility":3,"archive_timestamp":"2026-02-02T00:03:46+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-badgerdao-hack-december-2021","name":"","type":"other","archive_url":"http://web.archive.org/web/20260513012528/https://www.halborn.com/blog/post/explained-the-badgerdao-hack-december-2021","credibility":3,"archive_timestamp":"2026-05-13T01:25:28+00:00"},{"url":"https://zengo.com/the-badgerdao-hack-what-really-happened-and-why-it-matters/","name":"","type":"other","archive_url":"http://web.archive.org/web/20250917115107/https://zengo.com/the-badgerdao-hack-what-really-happened-and-why-it-matters/","credibility":3,"archive_timestamp":"2025-09-17T11:51:07+00:00"},{"url":"https://www.bloomberg.com/news/articles/2021-12-10/badgerdao-says-cloudflare-flaw-led-to-130-million-heist","name":"","type":"other","archive_url":"http://web.archive.org/web/20250902222831/https://www.bloomberg.com/news/articles/2021-12-10/badgerdao-says-cloudflare-flaw-led-to-130-million-heist","credibility":3,"archive_timestamp":"2025-09-02T22:28:31+00:00"},{"url":"https://www.theblock.co/post/126072/defi-protocol-badgerdao-exploited-for-120-million-in-front-end-attack","name":"","type":"other","archive_url":"http://web.archive.org/web/20260725164711/https://www.theblock.co/post/126072/defi-protocol-badgerdao-exploited-for-120-million-in-front-end-attack","credibility":3,"archive_timestamp":"2026-07-25T16:47:11+00:00"},{"url":"https://beincrypto.com/badgerdao-post-mortem-details-fourth-largest-defi-exploit/","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://blockworks.co/news/hackers-drain-115-million-from-bitcoin-defi-focused-badgerdao","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"forbiddenaccess","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.coindesk.com/markets/2021/12/03/crypto-lender-celsius-admits-losses-in-120m-badgerdao-hack","name":"","type":"other","archive_url":"https://web.archive.org/web/20260916004734/https://www.coindesk.com/markets/2021/12/03/crypto-lender-celsius-admits-losses-in-120m-badgerdao-hack","credibility":3,"archive_timestamp":"2026-09-16T00:47:34+00:00"},{"url":"https://cryptopotato.com/celsius-network-reportedly-lost-50-million-in-the-120-million-badgerdao-hack/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260725140215/https://cryptopotato.com/celsius-network-reportedly-lost-50-million-in-the-120-million-badgerdao-hack/","credibility":3,"archive_timestamp":"2026-07-25T14:02:15+00:00"},{"url":"https://www.chainalysis.com/blog/chainalysis-podcast-episode-6-badgerdao-hack/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260411084605/https://www.chainalysis.com/blog/chainalysis-podcast-episode-6-badgerdao-hack/","credibility":3,"archive_timestamp":"2026-04-11T08:46:05+00:00"},{"url":"https://forta.org/blog/how-to-derail-a-120-million-dollar-hack/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260411145532/https://forta.org/blog/how-to-derail-a-120-million-dollar-hack","credibility":3,"archive_timestamp":"2026-04-11T14:55:32+00:00"},{"url":"https://dailycoin.com/single-user-loses-50-million-bitcoin-in-badger-dao-hack/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260830125730/https://dailycoin.com/single-user-loses-50-million-bitcoin-in-badger-dao-hack/","credibility":3,"archive_timestamp":"2026-08-30T12:57:30+00:00"},{"url":"https://www.coindesk.com/tech/2021/12/16/after-130m-hack-badgers-restitution-plan-tests-limits-of-dao-governance","name":"","type":"other","archive_url":"http://web.archive.org/web/20260726005616/https://www.coindesk.com/tech/2021/12/16/after-130m-hack-badgers-restitution-plan-tests-limits-of-dao-governance","credibility":3,"archive_timestamp":"2026-07-26T00:56:16+00:00"},{"url":"https://ambcrypto.com/badgerdao-reveals-cause-behind-exploit-details-recovery-plan/","name":"","type":"other","archive_url":"http://web.archive.org/web/20250909173938/https://ambcrypto.com/badgerdao-reveals-cause-behind-exploit-details-recovery-plan/","credibility":3,"archive_timestamp":"2025-09-09T17:39:38+00:00"},{"url":"https://forum.badger.finance/t/bip-77-reactivate-smart-contracts-and-recover-funds/5178","name":"","type":"other","archive_url":"https://web.archive.org/web/20260830163509/https://forum.badger.finance/t/bip-77-reactivate-smart-contracts-and-recover-funds/5178","credibility":3,"archive_timestamp":"2026-08-30T16:35:09+00:00"},{"url":"https://www.dirtybubblemedia.com/p/an-inexplicable-error-cost-celsius","name":"","type":"other","archive_url":"http://web.archive.org/web/20260513185430/https://www.dirtybubblemedia.com/p/an-inexplicable-error-cost-celsius","credibility":3,"archive_timestamp":"2026-05-13T18:54:30+00:00"},{"url":"https://www.hoptrail.io/post/badgerdao-exploit-illustrating-celsius-poor-controls","name":"","type":"other","archive_url":"http://web.archive.org/web/20260118155912/https://www.hoptrail.io/post/badgerdao-exploit-illustrating-celsius-poor-controls","credibility":3,"archive_timestamp":"2026-01-18T15:59:12+00:00"},{"url":"https://defillama.com/protocol/badger-dao","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.tradingview.com/news/coindar:c3b007e7c094b:0-badger-dao-to-be-delisted-from-binance-on-april-16th/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260830133749/https://www.tradingview.com/news/coindar:c3b007e7c094b:0-badger-dao-to-be-delisted-from-binance-on-april-16th/","credibility":3,"archive_timestamp":"2026-08-30T13:37:49+00:00"},{"url":"https://www.cryptotimes.io/2025/04/09/binance-to-delist-14-tokens-after-community-vote/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260829202002/https://www.cryptotimes.io/2025/04/09/binance-to-delist-14-tokens-after-community-vote/","credibility":3,"archive_timestamp":"2026-08-29T20:20:02+00:00"},{"url":"https://coinmarketcap.com/cmc-ai/badger-dao/latest-updates/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260113162802/https://coinmarketcap.com/cmc-ai/badger-dao/latest-updates/","credibility":3,"archive_timestamp":"2026-01-13T16:28:02+00:00"},{"url":"https://redefine.net/media/badger-dao-attack/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829195023/https://redefine.net/lander","credibility":3,"archive_timestamp":"2026-08-29T19:50:23+00:00"},{"url":"https://www.microsoft.com/en-us/security/blog/2022/02/16/ice-phishing-on-the-blockchain/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260526164121/https://www.microsoft.com/en-us/security/blog/2022/02/16/ice-phishing-on-the-blockchain/","credibility":3,"archive_timestamp":"2026-05-26T16:41:21+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-5","created_at":"2026-05-04T02:54:52.939659+00:00","updated_at":"2026-09-16T00:50:17.708597+00:00"}}