Exploit in MakerDAO could allow a hacker to steal over $300 million in collateral

An independent developer released a blog post detailing how an attacker could purchase around 40,000 MKR tokens to gain control of governance and call a function issuing themselves all of the locked collateral. In addition, they could print infinite Dai which could then be used on platforms like Uniswap and Compound to permanently borrow assets.

This problem could have been mitigated by a delay function that would allow other stakeholders the ability to trigger a global shutdown thwarting the attackers, however, the parameter was set to 0 seconds. The Maker team has since responded by issuing a proposal to increase the Governance Security Module (GSM) delay to 24 hours.

Why it matters:

  • Dai and its Single Collateral counterpart Sai, comprise over 70% of the loans outstanding. If an attack like this were to be executed it would be devastating for the Open Finance movement, destroying more than $300 million of value, shattering trust in the system.
  • While the existence of the attack is worrying, it is promising that the Maker team was able to react and propose a fix for the community to vote on the same day. Decentralized governance networks are still in their early stages, but the discussion around potential attack vectors are able to make these systems more robust.
Let us know what you loved about the report, what may be missing, or share any other feedback by filling out this short form. All responses are subject to our Privacy Policy and Terms of Service.
Mentioned Assets

Suggested Research Based on your Watchlists

Create a new watchlist
Mentioned Assets