DeFi protocol BadgerDAO is investigating after security researchers say $120.3M was stolen from users via its compromised front end
Quick Take — DeFi protocol BadgerDAO was exploited earlier today for $120 million. — It appears that its front end was compromised and users were tricked into making unwanted transactions.
The Block Tim Copeland
Related Coverage
- Someone stole $120 million in crypto by hacking a DeFi website The Verge · Richard Lawler
- Hackers Steal $119M From ‘Web3’ Crypto Project With Old School Attack VICE · Lorenzo Franceschi-Bicchierai
- Celsius Reportedly Affected in Exploit of DeFi Protocol BadgerDAO Blockworks · Liz Coyne
- View article Security Affairs
- View article Crypto Briefing
- Crypto lending firm Celsius reportedly affected in BadgerDAO exploit Cointelegraph · Helen Partz
- DeFi protocol Badger DAO loses $120 million in exploit, sending prices in a downward spiral FXStreet · Ekta Mourya
- BadgerDAO DeFi defunded as hackers apparently nab millions in crypto tokens The Register · Thomas Claburn
- BadgerDAO Becomes Latest DeFi Protocol to Fall Victim to Security Breach Coinspeaker · Tolu Ajiboye
- Exploit Allows Hackers to Siphon $120 Million From Defi Protocol Badgerdao Bitcoin News · Jamie Redman
- BadgerDAO Hacked: $120 Million Allegedly Stolen (Updated) CryptoPotato · Jordan Lyanchev
- Badger DAO Protocol Suffers $120M Exploit CoinDesk · Andrew Thurman
- BadgerDAO reportedly suffers security breach, losing $120M Cointelegraph · Brian Newar
- $120M Lost in BadgerDAO DeFi Hack Crypto Briefing · Stefan Stankovic
- Bitcoin DeFi tool BadgerDAO hit by estimated $120 million hack CryptoSlate · Ana Grabundzija
Discussion
-
@badgerdao
@badgerdao
on x
Badger has received reports of unauthorized withdrawals of user funds. As Badger engineers investigate this, all smart contracts have been paused to prevent further withdrawals. Our investigation is ongoing and we will release further information as soon as possible.
-
@nexusmutual
Nexus Mutual
on x
🚨 BadgerDAO Loss Event 🚨 We're waiting for full details from the BadgerDAO team, but this appears to be a frontend attack. If this is confirmed as a frontend attack, BadgerDAO's smart contracts were not impacted & this would not be a covered event. https://twitter.com/... ⬇️
-
@lorenzofb
Lorenzo Franceschi-Bicchierai
on x
NEW: Hackers stole around $119 million from a cryptocurrency project by compromising an API key. As it turns out, so-called web3 can depend heavily on good old web1 security. https://www.vice.com/...
-
@arvidkahl
Arvid Kahl
on x
I hope these are just web3 growing pains. A comment on Hacker News reads “Reminder that every DAO is a self-administering bug bounty for all of the value under its control.” Interesting times. https://www.theblockcrypto.com/ ...
-
@notshenetworks
Shenetworks
on x
I guess we're not any closer to replacing TCP/IP with blockchain 😲 https://twitter.com/...
-
@briannekimmel
Bri Kimmel
on x
Members of DAOs may share similar values, but they're still strangers you've met on the internet. I'm seeing usually responsible people sharing home address & personal information in Discord, WhatsApp, etc. Please be safe! https://www.vice.com/...
-
@0xtaiga
Taiga
on x
Might be a good idea for protocols to purchase @ensdomains for their contracts so people can easily check what contracts they interact with on @MetaMask https://twitter.com/...
-
@johnkoetsier
John Koetsier
on x
“One user had around 900 bitcoin ($50.8 million) worth of tokens stolen in a single transaction. Another lost $5 million worth of tokens in one go.” Ouch ouch ouch ouch!!! DeFi protocol BadgerDAO exploited for $120 million in front-end attack https://www.theblockcrypto.com/ ...
-
@lorenzofb
Lorenzo Franceschi-Bicchierai
on x
Spoke to two people who work for the hacked organization, BadgerDAO. They said someone compromised an API key and then tricked “people into giving the address rights to send the tokens” to the hacker's address. @dguido explains what went wrong here. https://www.vice.com/... https…
-
@s_m_i
Stacy-Marie Ishmael
on x
“As it turns out, so-called web3 can depend heavily on good old web1 security.” everything old is new in crypto https://www.vice.com/...
-
@joshmcgruff
@joshmcgruff
on x
This whole space is just one big beta test https://twitter.com/...
-
@charlesarthur
Charles Arthur
on x
“Why do these hacks keep happening, say people in field where being hacked means irretrievable loss to everyone but the hacker” https://twitter.com/...
-
@johnmgran
John M.
on x
“if the front end gets comprised, as in this case, then it can lead to loss of funds.” We can reduce the risk by hosting and running #Elastos #Web3 DApps inside @ElaboxDotCom Heads down and build 🛠️👨 💻 https://twitter.com/...
-
@pinboard
@pinboard
on x
Another day, another $120M cryptocurrency theft. The mechanism here highlights a point I made before—given a set of decentralized, unusable tools, civilians will gravitate to centralized, easy to use tools like the website that just stole all their money. https://www.theblockcryp…