MakerDAO Legacy Auction Keeper Exploit (October 2026)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·4EaaVb…LvFPSummary
On October 6, 2026, an attacker drained approximately 200 ETH (roughly $538,000-$543,000) from a dormant, third-party MakerDAO liquidation keeper contract by exploiting a missing access-control check on one function, then settling four long-abandoned zero-bid auctions left over from the March 2020 'Black Thursday' crash. MakerDAO's (now Sky's) core protocol contracts (Vat, Flipper, GemJoin) functioned as designed and were not breached; the vulnerability resided entirely in a third-party keeper implementation that had been inactive for roughly six years. The incident has been cited as an example of dormant legacy DeFi infrastructure becoming a profitable attack surface years after it stopped being actively used.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Timeline(5 events)
March 2020
During the 'Black Thursday' market crash, a MakerDAO liquidation keeper contract wins four ETH-A collateral auctions (lots 1457-1460, 50 ETH each) with zero bids, but never calls deal() to claim the collateral, leaving 200 ETH locked in the Flipper auction contract.
Protos / CertiK6 October 2026
An attacker funds a wallet with a 0.1 ETH Tornado Cash withdrawal, deploys an attack contract, and exploits function 0x8804d1de in the dormant keeper implementation, gaining delegated control of the keeper's MakerDAO Vat account and settling the four unclaimed 2020 auctions to extract 200 ETH (approximately $538,000-$543,000).
Crypto Times / CertiKOctober 2026
Roughly six minutes after the exploit, the attacker begins moving the stolen ETH back into Tornado Cash in multiple batches.
CertiK / KuCoin NewsOctober 2026
On-chain monitoring accounts (Defimon Alerts, Cryptoiz Research) publicly flag the exploit and state that MakerDAO's core Vat, Flipper, and GemJoin contracts behaved as designed and were not breached.
Crypto TimesOctober 2026
CertiK publishes a detailed incident analysis and Protos and KuCoin News publish coverage confirming the missing access control root cause.
ProtosDecision Log
- slot 454988760 · hash EmJCTYGccLBh23WzHJY6DEMjaWRMRb7Juc7jGhivNkYp
This investigation is cryptographically anchored to the Solana blockchain (1 decision). 1 of 4 cited source URLs have an Internet Archive snapshot.
model: claude-code-investigator
generated: 10/9/2026, 8:18:20 PM
last updated: 10/9/2026, 8:18:21 PM
avoid.net — verified advice for a post-truth world