{"investigation":{"slug":"tapioca-dao","entity_name":"Tapioca DAO","trust_score":12,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"Tapioca DAO is an omnichain DeFi money market built on LayerZero, offering a CDP stablecoin (USDO) and isolated lending markets (Singularity/Big Bang) across Arbitrum and BNB Chain. On October 18, 2024, the protocol suffered a critical security breach when a team member was targeted by a social engineering attack attributed to North Korea's Contagious Interview campaign, resulting in private key compromise, drainage of TAP token vesting contracts, and the minting of 5 quintillion USDO. Approximately $4.4–4.7 million was stolen before a partial counter-exploit recovered roughly 996 ETH (~$2.7 million), leaving the protocol treasury down approximately 45% and the TAP token price collapsed over 95%.","sections":[{"content":"Tapioca DAO is an omnichain decentralized finance (DeFi) money market protocol that leverages LayerZero V2 messaging infrastructure to enable cross-chain borrowing, lending, and stablecoin issuance. The protocol's core products include Singularity (an omnichain isolated money market), Big Bang (an omnichain CDP stablecoin creation engine), and USDO, an over-collateralized stablecoin pegged to the US dollar and backed by decentralized gas tokens and liquid staking tokens (LSTs). USDO was implemented using LayerZero's OFT V2 (Omnichain Fungible Token) superstandard, enabling transfers across EVM and non-EVM chains without bridges, slippage, or wait times. The protocol's native governance and utility token is TAP, which also uses the LayerZero OFT V2 standard. Primary chain deployments include Arbitrum and BNB Chain. Prior to the October 2024 exploit, the protocol held significant liquidity tracked on DeFiLlama.","heading":"Protocol Overview","sources":[],"severity":"medium"},{"content":"On October 18, 2024, at approximately 12:00 PM UK time, Tapioca DAO suffered a critical security breach. The attack vector was social engineering rather than a smart contract vulnerability. According to co-founder Matt Marino, a Discord member identified as 0xRektora — a key team member with access to privileged protocol controls — was approached under the pretext of a friend seeking employment. The conversation lowered 0xRektora's guard sufficiently for the attacker to induce him to connect a hardware wallet, through which the attacker gained ownership of the TAP token vesting contract. Security firm Fuzzland and ZachXBT both indicated this method is consistent with the North Korean 'Contagious Interview' campaign, in which threat actors pose as job recruiters or interview subjects to trick targets into executing malware or exposing credentials. The attack exploited the Emergency Rescue function on the TAP vesting contract, enabling the attacker to withdraw approximately 28–30 million vested TAP tokens. These tokens were swapped for approximately 591 ETH, causing TAP's market price to collapse 93–97% from roughly $1.43 to under $0.05. The attacker subsequently compromised the USDO stablecoin contract and executed a multicall that minted approximately 5 quintillion USDO tokens. The stablecoin minting was ultimately contained before causing broader contagion, but the attacker drained approximately $2.8 million in USDC from the USDO/USDC Uniswap liquidity pool, as well as approximately $1.58 million in ETH from the same pool. Stolen assets were converted to USDT and bridged from Arbitrum to BNB Chain via the Stargate bridge.","heading":"October 2024 Hack: Social Engineering and Private Key Compromise","sources":[],"severity":"medium"},{"content":"ZachXBT publicly stated that the Tapioca DAO exploit may be part of a broader pattern of hacks targeting DeFi protocols, including Nexera, Concentric, Masa, SpaceCatch, Reach, Serenity Shield, and MurAll. He attributed these attacks to 'state-sponsored threat actors from North Korea' operating through fake job scam vectors — a pattern consistent with the Lazarus Group subgroup known as 'Contagious Interview' (also tracked as DEV#POPPER, TAG-121, and Group G1052 by MITRE ATT&CK). The Contagious Interview campaign, first documented in 2023 by SentinelOne, involves North Korean threat actors targeting crypto developers and employees through fake job postings and fraudulent interview processes to deliver malware and harvest private keys. CoinDesk has separately documented this campaign as a widespread and growing vector across crypto. At the time of initial reporting by CryptoSlate (October 2024), no conclusive on-chain forensic evidence had been published directly linking the Tapioca exploit addresses to confirmed Lazarus Group wallets. The attribution rests on behavioral pattern analysis and ZachXBT's cross-case linkage, which are assessed as medium-confidence indicators.","heading":"North Korea / Lazarus Group Attribution","sources":[],"severity":"medium"},{"content":"Following the breach, Tapioca's security team, working with emergency response group SEAL911 and security firm EnigmaDarkLabs (also referenced as Fuzzland in some reports), identified that the attacker had not yet laundered approximately 1,000 ETH held in a position the attacker had overlooked. The team executed a counter-exploit — the technical details of which were deliberately withheld — to recover 996 ETH (approximately $2.7 million at the time) before the attacker could move or launder those funds. Tapioca announced: 'We have hacked the hacker! Recovered 1000 ETH which is now safely in the DAO multisig.' This counter-recovery is consistent with a precedent set in 2023 when Oasis developers reclaimed $140 million following the Wormhole bridge hack. Tapioca also offered the attacker a $1 million USDT bounty — described as 'significantly higher than the normal 10%' white-hat bounty — in exchange for returning the remaining approximately $3.7 million in stolen funds. The attacker did not comply, and the bounty offer was subsequently revoked after the October 22, 2024 deadline passed. Following recovery, the DAO treasury excluding TAP tokens stood at approximately $4.2–4.8 million, representing a loss of approximately 45% from its pre-attack position.","heading":"Counter-Exploit and Fund Recovery","sources":[],"severity":"medium"},{"content":"The following on-chain addresses were identified in connection with the October 2024 exploit. The TAP vesting contract targeted by the attacker is at 0x2997C5ddD3070A46E9938261ce0A16a237121cb0 on Arbitrum. The primary exploiter address is 0x70285a11489bed93686410EBC727057CAfb8129D. The USDO stablecoin contract subjected to the infinite mint exploit is 0xEB99062643cA5Ab880c077288345E0B14B297432. Stolen funds were bridged and consolidated at BNB Chain address 0x69d91e56ca80f2a4d7b808b59053ea5c5505ffe2. One USDO exploit transaction hash identified in connection with the attack is 0x0bca43cfb5b14ea039f2b329cb6074383d54ed8240963014ccb6400befa5a4e3. These addresses are drawn from secondary reporting and have not been independently verified against official forensic reports as of the time of this investigation.","heading":"On-Chain Addresses of Interest","sources":[],"severity":"medium"},{"content":"The TAP token experienced a catastrophic price collapse coinciding with the exploit. From a pre-attack price of approximately $1.40–$1.43, TAP fell to approximately $0.04–$0.05, representing a decline of 93–97% within hours of the attack on October 18, 2024. The attacker withdrew approximately 28–30 million TAP tokens from the vesting contract and swapped them for 591 ETH, exhausting available liquidity and causing the token price collapse. TAP is available on CoinMarketCap and other tracking platforms but, as of this investigation, has not recovered to pre-hack price levels. Investors holding TAP at the time of the attack suffered near-total losses on their token positions.","heading":"TAP Token and Market Impact","sources":[],"severity":"medium"},{"content":"In the wake of the breach, CryptoSlate and other outlets reported the emergence of secondary phishing attacks targeting Tapioca DAO users. Fake accounts impersonating the official @tapioca_dao handle posted phishing links falsely promising refunds or compensation to affected users. This secondary scam wave is a common pattern following high-profile DeFi exploits and represents an additional risk to users seeking information or remedy in the post-exploit period.","heading":"Post-Exploit Phishing Activity","sources":[],"severity":"medium"}],"timeline":[{"date":"2024-10-18","event":"Tapioca DAO exploit begins at approximately 12:00 PM UK time. Attacker, having compromised 0xRektora's private keys via social engineering, triggers Emergency Rescue function on TAP vesting contract and withdraws approximately 28–30 million TAP tokens.","source":"","source_url":"https://www.dlnews.com/articles/defi/tapioca-dao-tap-token-plummets-after-founder-suffers-hack/"},{"date":"2024-10-18","event":"TAP token price collapses 93–97%, from approximately $1.43 to under $0.05, as attacker swaps 30 million TAP for 591 ETH.","source":"","source_url":"https://www.theblock.co/post/322061/tapioca-dao-stops-1000-eth-worth-2-7-million-from-being-stolen-following-exploit-that-drains-majority-of-its-funds"},{"date":"2024-10-18","event":"Attacker compromises USDO stablecoin contract and mints approximately 5 quintillion USDO. Approximately $2.8 million USDC and $1.58 million ETH drained from USDO/USDC Uniswap pool. Stolen assets bridged from Arbitrum to BNB Chain via Stargate.","source":"","source_url":"https://www.halborn.com/blog/post/explained-the-tapioca-dao-hack-october-2024"},{"date":"2024-10-18","event":"Tapioca Foundation, with assistance from SEAL911 and EnigmaDarkLabs/Fuzzland, executes counter-exploit recovering 996 ETH (~$2.7 million) from attacker before it could be laundered.","source":"","source_url":"https://www.dlnews.com/articles/defi/tapioca-dao-hacks-its-hacker-after-north-korean-attack/"},{"date":"2024-10-18","event":"ZachXBT publicly links the Tapioca DAO attack to a broader pattern of DeFi hacks (Nexera, Concentric, Masa, SpaceCatch, Reach, Serenity Shield, MurAll) attributed to North Korean state-sponsored threat actors using Contagious Interview / fake job scam vectors.","source":"","source_url":"https://cryptoslate.com/north-korea-links-suspected-in-5-million-breach-of-tapioca-dao/"},{"date":"2024-10-19","event":"Tapioca DAO offers attacker a $1 million USDT white-hat bounty with a deadline of October 22, 2024, in exchange for returning approximately $3.7 million in stolen funds.","source":"","source_url":"https://cryptohead.io/news/tapioca-dao-offers-1m-bounty-after-4-7m-hack/"},{"date":"2024-10-22","event":"Bounty deadline passes with no response from attacker. Tapioca DAO revokes the $1 million bounty offer.","source":"","source_url":"https://www.dlnews.com/articles/defi/tapioca-dao-hacks-its-hacker-after-north-korean-attack/"},{"date":"2024-10-22","event":"Tapioca Foundation publishes post-mortem on Mirror identifying attack as social engineering / Contagious Interview method and attributing it to a North Korean group. DAO treasury reported at approximately $4.2–4.8 million, down ~45% from pre-attack.","source":"","source_url":"https://rekt.news/tapioca-dao-rekt"}],"sources_used":[],"source_tags":["defillama","zachxbt"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet","created_at":"2026-05-04T02:54:28.354053+00:00","updated_at":"2026-08-29T01:35:57.297+00:00"}}