MakerDAO Legacy Contract Exploited for $500K in Black Thursday Echo
Attacker drains 200 ETH from forgotten MakerDAO contract
A legacy MakerDAO auction-keeper contract has been exploited for more than $500,000, with the vulnerability tracing back to the March 2020 market crash known as Black Thursday.
According to an analysis by security firm CertiK, an attacker removed 200 ETH from a contract identified as a "legacy auction-keeper." The funds came from four lots of 50 ETH each that had remained unsettled since the original liquidation crisis six years ago.
The Black Thursday connection
During Black Thursday in March 2020, MakerDAO faced a massive liquidation event as the price of ETH dropped sharply. Several auction-keeper contracts, including the one now exploited, won ETH from MakerDAO for "zero bids" during the chaos. Four 50-ETH lots from that period were never settled, leaving value sitting in the contract untouched.
The attacker discovered and exploited those unresolved lots, draining the ETH and sending it through Tornado Cash — a mixing service used to obscure the trail of transactions — in 10-ETH chunks.
What CertiK found
CertiK's analysis identified the root cause as a missing access control function. Specifically, the keeper implementation at address 0x68399ed8aa33C5b43F863EE6782de492006A5546 lacked proper permissions checks on function 0x8804d1de, allowing anyone to withdraw funds meant only for authorized operators.
Old contracts, old risks
The exploited contract was not part of MakerDAO's current Sky ecosystem, which launched after the protocol's rebranding. However, the incident highlights what the source describes as "the long tail of cryptocurrency risks" — even contracts inactive for half a decade can remain lucrative targets if they still hold real value.
What is confirmed
The exploit occurred, 200 ETH was removed from the legacy auction-keeper contract, and the funds were moved through Tornado Cash, according to CertiK's analysis and on-chain data. The vulnerability stemmed from a missing access control check.
What remains unclear
The source does not confirm whether the attacker has been identified or whether recovered funds are being tracked. It is also unclear whether MakerDAO or Sky will take any action regarding the vulnerable legacy contract.
Why this matters
The incident serves as a reminder that dormant smart contracts on blockchains can retain value for years and remain vulnerable to exploitation. Even contracts no longer used by a project can be targeted if they hold funds and lack proper security controls.