An attacker withdrew 200 ETH, worth about $543,000, from a legacy MakerDAO contract on Ethereum on Oct. 6, 2026, according to findings cited by CertiK. The funds were taken from an old auction keeper linked to liquidations from the March 2020 market crash known as “Black Thursday.”
The reported weakness was a missing access-control check in one function of the contract. That flaw allegedly let the attacker take control of the keeper’s account inside MakerDAO’s Vat accounting system, settle several long-unfinished auctions, and then remove the resulting ETH.
Legacy contract exposed old liquidation positions
The compromised contract was described as a legacy auction keeper that still held collateral connected to MakerDAO liquidations from March 2020. Those liquidations happened during the severe market disruption often referred to as Black Thursday.
According to the report, the keeper had won four auctions in 2020 with zero bids but never completed payment for them. Those unfinished positions later became the economic basis for the exploit, because closing them would credit value to the keeper’s account in Vat.
Missing check opened the path to control
The core issue was a function identified as 0x8804d1de. Unlike other privileged functions in the contract, it reportedly lacked an access-rights check and could be used to delegate authority to an arbitrary address through MakerDAO Vat.
The attacker is said to have deployed a custom contract at 06:12 UTC after first funding an address with 0.1 ETH through Tornado Cash. About a minute later, a transaction was sent that enabled access to the assets held by the old keeper contract.
Exploit chain ended with four auction settlements
The reported attack sequence involved creating an adapter module and supplying its address to the vulnerable keeper function. The keeper then granted that module full control over its Vat account via Vat.hope(), after which it called the module’s join() function, effectively handing execution to the attacker.
From there, the attacker settled four old auctions, numbered 1457, 1458, 1459, and 1460. Each auction reportedly contained a 50 ETH lot. Once the auctions were closed, a total of 200 ETH was credited to the keeper account in Vat, and the attacker withdrew those funds using the delegated permissions.
Stolen ETH moved quickly toward mixing service
The full 200 ETH reportedly reached the attacker in a single exploit transaction roughly one minute after the attack began. Transaction analysis cited in the report said the first transfer to Tornado Cash took place six minutes later.
The funds were then split into 10 ETH deposits, with analysis indicating the use of a Tornado Cash router. The article did not identify the attacker or mention any immediate recovery of the stolen ETH.
What is confirmed so far
Based on the published account, the exploit depended on a dormant weakness in older infrastructure rather than a newly created auction position. The four unfinished Black Thursday auctions appear to have been the specific source of the 200 ETH that was ultimately withdrawn.
The confirmed next step from the available information is on-chain tracing of the stolen funds, which had already begun moving through Tornado Cash shortly after the exploit. No further official response or remediation details were provided in the source material.
Source: incrypted.com