Advertisement
UK markets close in 7 hours 39 minutes
  • FTSE 100

    8,126.17
    +47.31 (+0.59%)
     
  • FTSE 250

    19,733.05
    +131.07 (+0.67%)
     
  • AIM

    755.67
    +2.55 (+0.34%)
     
  • GBP/EUR

    1.1656
    -0.0001 (-0.01%)
     
  • GBP/USD

    1.2508
    -0.0003 (-0.03%)
     
  • Bitcoin GBP

    51,445.21
    +286.89 (+0.56%)
     
  • CMC Crypto 200

    1,388.67
    -7.87 (-0.56%)
     
  • S&P 500

    5,048.42
    -23.21 (-0.46%)
     
  • DOW

    38,085.80
    -375.12 (-0.98%)
     
  • CRUDE OIL

    84.01
    +0.44 (+0.53%)
     
  • GOLD FUTURES

    2,356.70
    +14.20 (+0.61%)
     
  • NIKKEI 225

    37,934.76
    +306.28 (+0.81%)
     
  • HANG SENG

    17,645.83
    +361.29 (+2.09%)
     
  • DAX

    18,011.66
    +94.38 (+0.53%)
     
  • CAC 40

    8,036.30
    +19.65 (+0.25%)
     

Badger DAO Protocol Suffers $120M Exploit

A decentralized finance (DeFi) mainstay is the latest to fall victim to a hack following the loss of $120 million in various cryptocurrencies.

On Wednesday night an attacker drained funds from the wallets of dozens of users of the Badger DAO yield vault protocol using malicious contract permissions. Blockchain data and security analytics company PeckShield has concluded that the total loss amounted to about 2,100 BTC and 151 ETH.

Users first reported possible problems in the protocol’s channel on the Discord messaging app at 9 p.m. ET Wednesday. Speculation in online channels is that the hack is the result of an exploit in the Badger.com user interface, and not in the core protocol contracts. Many affected users report that while claiming yield farming rewards and interacting with Badger vaults, they noticed their wallet providers prompting spurious requests for additional permissions.

“It looks like a bunch of users had approvals set for the exploit address allowing [the address] to operate on their vault funds and that was exploited,” Badger core contributor Tritium wrote on Discord.

ADVERTISEMENT

“Once we noticed we froze all the vaults so nothing can move and are trying to figure out where the approvals came from, how many people have them, and what next steps are,” he added.

Badger’s official social media channel confirmed the hack on Twitter:

A Badger representative didn’t respond to a request for comment by the time of publication.

While the bulk of the funds were drained Wednesday night, the malicious permission requests may have been made weeks prior to the attack. Though the protocol contracts are paused, community members are advising that depositors use tools like Debank and Unrekt to revoke permissions for the malicious contract.

At the time of writing BadgerDAO’s BADGER token was down 21% to $21.64 over the past 24 hours.

UPDATE (Dec. 2, 11:10 UTC): Updates estimate of amount stolen, token price.