MakerDAO bug could’ve let hackers steal Ethereum powering its DAI stablecoin

MakerDAO ($MKR) has disclosed a security flaw in their upcoming Multi-Collateral Dai system that could have allowed an attacker to steal all of the collateral. A disclosure report reveals that:

"A lack of validation in the method flip.kick allows an attacker to create an auction with a fake bid value. Since the end contract trusts that value, it can be exploited to issue any amount of free $Dai during liquidation. That Dai can then be immediately used to obtain all collateral stored in the end contract."

Currently, there is over 1.5 million $ETH locked in Maker (1.4% of the total supply) worth over $250 million.

Let us know what you loved about the report, what may be missing, or share any other feedback by filling out this short form. All responses are subject to our Privacy Policy and Terms of Service.
Mentioned Assets

Suggested Research Based on your Watchlists

Create a new watchlist
Mentioned Assets