{"investigation":{"slug":"makerdao-legacy-auction-keeper-exploit-october-2026","entity_name":"MakerDAO Legacy Auction Keeper Exploit (October 2026)","trust_score":35,"severity_base":null,"score_modifier":0,"confidence":0.75,"status":"published","content_type":"investigation","summary":"On October 6, 2026, an attacker drained approximately 200 ETH (roughly $538,000-$543,000) from a dormant, third-party MakerDAO liquidation keeper contract by exploiting a missing access-control check on one function, then settling four long-abandoned zero-bid auctions left over from the March 2020 'Black Thursday' crash. MakerDAO's (now Sky's) core protocol contracts (Vat, Flipper, GemJoin) functioned as designed and were not breached; the vulnerability resided entirely in a third-party keeper implementation that had been inactive for roughly six years. The incident has been cited as an example of dormant legacy DeFi infrastructure becoming a profitable attack surface years after it stopped being actively used.","sections":[{"content":"At approximately 06:13:11 UTC on October 6, 2026, an attacker exploited function selector 0x8804d1de in a legacy MakerDAO auction-keeper implementation contract (address 0x68399ed8aa33C5b43F863EE6782de492006A5546), used via an upgradeable proxy. According to CertiK's incident analysis, as reported by Protos and CryptoTimes, the function allowed any caller to supply an arbitrary 'adapter' module address, which the keeper then granted full delegated authority over its MakerDAO Vat account (via Vat.hope) before calling back into the attacker-controlled module. Unlike other privileged functions in the same contract, which enforced a ds-auth permission check and reverted for unauthorized callers, this function performed no such check. The attacker's malicious module used the delegated authority to call deal() on a retired ETH-A Flipper auction contract, settling four 50-ETH auction lots (auction IDs 1457-1460) that the keeper had won with zero bids during the March 2020 'Black Thursday' market crash but had never claimed. The resulting 200 ETH of collateral was then moved out via Vat.flux and exited through the ETH-A GemJoin as WETH to an address controlled by the attacker. Reported dollar values for the loss range from approximately $538,000 to $543,000, reflecting ETH's price at the time.","heading":"The Exploit","sources":[{"url":"https://www.certik.com/blog/makerdao-legacy-auction-keeper-incident-analysis","name":"MakerDAO Legacy Auction Keeper Incident Analysis - CertiK","type":"research","credibility":2},{"url":"https://protos.com/black-thursday-revisited-makerdao-keeper-exploited-for-500k/","name":"Black Thursday revisited: MakerDAO keeper exploited for $500K - Protos","type":"news_article","credibility":2},{"url":"https://www.cryptotimes.io/2026/10/06/dormant-makerdao-keeper-drained-of-538k-core-remains-intact/","name":"Dormant MakerDAO Keeper Drained of $538K, Core Remains Intact - Crypto Times","type":"news_article","credibility":2}],"severity":"high"},{"content":"CertiK's analysis identified the root cause as a missing access-control check on the vulnerable function. Other privileged functions in the same keeper implementation (such as hope, flux, and move wrappers) enforced a ds-auth check and would revert with a 'ds-auth-unauthorized' error for unauthorized callers; the exploited function did not have this protection, allowing any external address to invoke it. Additionally, the function never called a corresponding 'nope' function to revoke the delegated Vat authority it granted, meaning the malicious module's control over the keeper's Vat account persisted after the transaction completed. The vulnerability was exploitable only because the keeper itself held value in the form of four unsettled 2020 auction lots; CertiK noted that calling deal() on a MakerDAO auction is permissionless by design, so anyone could trigger settlement once they had obtained delegated authority over the keeper's account.","heading":"Root Cause: Missing Access Control","sources":[{"url":"https://www.certik.com/blog/makerdao-legacy-auction-keeper-incident-analysis","name":"MakerDAO Legacy Auction Keeper Incident Analysis - CertiK","type":"research","credibility":2},{"url":"https://www.kucoin.com/news/insight/ETH/6ac6b7c238a2640007930f31","name":"MakerDAO hit by a $543K exploit rooted in a 6-year-old bug - KuCoin News","type":"news_article","credibility":2}],"severity":"high"},{"content":"Reporting indicates the attacker's externally owned account was funded with a single 0.1 ETH withdrawal from a Tornado Cash pool prior to the attack, which CertiK's analysis states was the account's only funding source. Within roughly six minutes of the exploit transaction, the attacker began moving the stolen ETH back into Tornado Cash in batches. Sources vary on the exact batch size and count: some report 10-ETH deposits, while CertiK's own writeup shows an internal inconsistency between describing the first deposit as one of 'nine' or '20' total deposits. The requester's description of 'ten batches' is consistent with reporting but could not be independently confirmed with precision across all sources, so this detail should be treated as approximate.","heading":"Laundering via Tornado Cash","sources":[{"url":"https://www.certik.com/blog/makerdao-legacy-auction-keeper-incident-analysis","name":"MakerDAO Legacy Auction Keeper Incident Analysis - CertiK","type":"research","credibility":2},{"url":"https://protos.com/black-thursday-revisited-makerdao-keeper-exploited-for-500k/","name":"Black Thursday revisited: MakerDAO keeper exploited for $500K - Protos","type":"news_article","credibility":2},{"url":"https://www.kucoin.com/news/insight/ETH/6ac6b7c238a2640007930f31","name":"MakerDAO hit by a $543K exploit rooted in a 6-year-old bug - KuCoin News","type":"news_article","credibility":2}],"severity":"medium"},{"content":"Multiple sources, including on-chain monitoring accounts cited by Crypto Times and CertiK's own analysis, state that MakerDAO's core protocol contracts (the Vat accounting engine, the retired ETH-A Flipper auction contract, and the ETH-A GemJoin adapter) behaved exactly as designed throughout the incident and were not themselves compromised. The vulnerability was confined to a third-party liquidation keeper bot — software built to interact with MakerDAO's auctions but not part of the core protocol maintained by MakerDAO or its successor, Sky. Protos reported that the exploited contract 'wasn't a core part of the current Sky ecosystem,' and that the keeper had been dormant, holding unclaimed collateral, for approximately six years since the March 2020 Black Thursday liquidations.","heading":"Scope: Core Protocol Unaffected","sources":[{"url":"https://www.cryptotimes.io/2026/10/06/dormant-makerdao-keeper-drained-of-538k-core-remains-intact/","name":"Dormant MakerDAO Keeper Drained of $538K, Core Remains Intact - Crypto Times","type":"news_article","credibility":2},{"url":"https://protos.com/black-thursday-revisited-makerdao-keeper-exploited-for-500k/","name":"Black Thursday revisited: MakerDAO keeper exploited for $500K - Protos","type":"news_article","credibility":2}],"severity":"medium"},{"content":"Several outlets framed the incident as part of a broader pattern in which old, inactive DeFi contracts that still hold real value remain exploitable years after they stop being actively maintained or monitored. Protos observed that 'even contracts that haven't been central for half a decade can still be lucrative targets for attackers if they contain real value.' This incident followed the four unsettled 50-ETH auction lots from the March 2020 Black Thursday crisis sitting unclaimed in a retired Flipper contract for roughly six years before being discovered and drained. No regulatory or law-enforcement action related to this specific incident had been reported as of the time of this writing, and the identity of the attacker has not been publicly established.","heading":"Pattern: Dormant Legacy Contracts as Attack Surface","sources":[{"url":"https://protos.com/black-thursday-revisited-makerdao-keeper-exploited-for-500k/","name":"Black Thursday revisited: MakerDAO keeper exploited for $500K - Protos","type":"news_article","credibility":2}],"severity":"low"}],"timeline":[{"date":"2020-03","event":"During the 'Black Thursday' market crash, a MakerDAO liquidation keeper contract wins four ETH-A collateral auctions (lots 1457-1460, 50 ETH each) with zero bids, but never calls deal() to claim the collateral, leaving 200 ETH locked in the Flipper auction contract.","source":"Protos / CertiK","source_url":"https://protos.com/black-thursday-revisited-makerdao-keeper-exploited-for-500k/"},{"date":"2026-10-06","event":"An attacker funds a wallet with a 0.1 ETH Tornado Cash withdrawal, deploys an attack contract, and exploits function 0x8804d1de in the dormant keeper implementation, gaining delegated control of the keeper's MakerDAO Vat account and settling the four unclaimed 2020 auctions to extract 200 ETH (approximately $538,000-$543,000).","source":"Crypto Times / CertiK","source_url":"https://www.cryptotimes.io/2026/10/06/dormant-makerdao-keeper-drained-of-538k-core-remains-intact/","date_evidence":"the exploit transaction was included in Ethereum block 26,131,471 on October 6, 2026, at 06:13:11 UTC"},{"date":"2026-10","event":"Roughly six minutes after the exploit, the attacker begins moving the stolen ETH back into Tornado Cash in multiple batches.","source":"CertiK / KuCoin News","source_url":"https://www.kucoin.com/news/insight/ETH/6ac6b7c238a2640007930f31","date_original":"2026-10-06"},{"date":"2026-10","event":"On-chain monitoring accounts (Defimon Alerts, Cryptoiz Research) publicly flag the exploit and state that MakerDAO's core Vat, Flipper, and GemJoin contracts behaved as designed and were not breached.","source":"Crypto Times","source_url":"https://www.cryptotimes.io/2026/10/06/dormant-makerdao-keeper-drained-of-538k-core-remains-intact/","date_original":"2026-10-06"},{"date":"2026-10","event":"CertiK publishes a detailed incident analysis and Protos and KuCoin News publish coverage confirming the missing access control root cause.","source":"Protos","source_url":"https://protos.com/black-thursday-revisited-makerdao-keeper-exploited-for-500k/","date_original":"2026-10-07"}],"sources_used":[{"url":"https://www.certik.com/blog/makerdao-legacy-auction-keeper-incident-analysis","name":"MakerDAO Legacy Auction Keeper Incident Analysis - CertiK","type":"research","archive_url":null,"credibility":2,"archive_timestamp":null},{"url":"https://protos.com/black-thursday-revisited-makerdao-keeper-exploited-for-500k/","name":"Black Thursday revisited: MakerDAO keeper exploited for $500K - Protos","type":"news_article","archive_url":null,"credibility":2,"archive_timestamp":null},{"url":"https://www.cryptotimes.io/2026/10/06/dormant-makerdao-keeper-drained-of-538k-core-remains-intact/","name":"Dormant MakerDAO Keeper Drained of $538K, Core Remains Intact - Crypto Times","type":"news_article","archive_url":"http://web.archive.org/web/20261006200447/https://www.cryptotimes.io/2026/10/06/dormant-makerdao-keeper-drained-of-538k-core-remains-intact/","credibility":2,"archive_timestamp":"2026-10-06T20:04:47+00:00"},{"url":"https://www.kucoin.com/news/insight/ETH/6ac6b7c238a2640007930f31","name":"MakerDAO hit by a $543K exploit rooted in a 6-year-old bug - KuCoin News","type":"news_article","archive_url":null,"credibility":2,"archive_timestamp":null}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-code-investigator","created_at":"2026-10-09T20:18:20.815784+00:00","updated_at":"2026-10-09T21:16:47.505816+00:00"},"source_quality":{"total":4,"tier1":0,"tier2":1,"tier3":0,"unrated":3},"follower_count":null,"content_updated_at":"2026-10-09T20:18:21.122Z","last_fact_checked_at":null,"fact_check_next_allowed_at":null,"update_next_allowed_at":null}