CryptoReal
CASE FILE — Dec 2, 2021

A Poisoned Front End Let Attackers Siphon $120M From Badger DAO Depositors

Badger DAO has become the fourth-largest loss on record after attackers used a compromised front end to extract roughly $120 million in wrapped BTC and various ERC-20 tokens — not through a smart-contract bug, but by tricking users' own wallets into granting the attacker spending rights.

As rekt.news has observed before, granting infinite token approval is functionally an act of unlimited trust, something DeFi users are routinely warned against. This incident raises an uncomfortable follow-up question: even a careful user checking contract legitimacy through their wallet's approval prompts has no defense if the front end serving those prompts has itself been tampered with.

According to on-chain evidence, an unidentified party inserted extra approval requests into the site so that tokens would flow to an address they controlled. Beginning at 00:00:23 UTC on December 2, 2021, the attacker began drawing down on this pre-positioned trust, emptying wallets that had unknowingly granted access. Once reports of drained accounts reached the team, Badger announced it had paused the protocol's smart contracts; the fraudulent transactions started failing about two hours and twenty minutes after the attack began.

Badger DAO's stated purpose is bringing Bitcoin into DeFi through a set of vaults that let users earn yield on wrapped BTC variants on Ethereum. Most of the stolen assets were vault deposit tokens, which the attacker converted to cash out — bridging the underlying BTC back to the Bitcoin network while any remaining ERC-20 tokens stayed on Ethereum. A running tally of where the stolen funds ended up has been compiled separately. Unconfirmed reports have circulated that Badger's Cloudflare account was the point of compromise, alongside other security issues flagged by researchers.

Sums referenced in this case file

The malicious approvals were surfaced to users disguised as ordinary deposit and reward-claim transactions, gradually building a pool of unlimited wallet approvals that the attacker could later use to move BTC-related tokens straight out of victims' addresses. Per Peckshield, the earliest approval requests tied to the attacker's address date back roughly two weeks before the exploit was executed, meaning anyone who interacted with the platform in that window could have unknowingly authorized the drain. More than 500 addresses are recorded as having approved the attacker's address, 0x1fcdb04d0c5364fbd92c73ca8af9baa72c269107 (Etherscan). Users are advised to review and revoke any outstanding approvals via Etherscan's token approval checker.

One representative transaction illustrates the scale: an attack transaction drained roughly 900 byvWBTC, worth more than $50 million, from a victim address that had granted the attacker unlimited spending rights via the increaseAllowance() function roughly six hours earlier. The team was ultimately able to halt further losses thanks to an "unusual" property of Badger's transferFrom() function that allowed all activity to be paused.

The episode reinforces that even long-established, well-regarded protocols are not immune — Badger joins a list that includes near-misses at some of DeFi's biggest names, such as Aave's xSUSHI incident — and underscores the value of diversifying exposure rather than assuming any single protocol is safe by reputation alone. Notably, the usual advice to verify URLs and use official channels would not have protected users here, since the compromise sat within the legitimate front end itself.

Peckshield's data indicates the front end had been manipulated for at least 12 days before the exploit, raising the question of why the anomaly went unnoticed for so long — particularly since a user had already flagged a suspicious increaseAllowance() approval in the project's Discord beforehand, without the team following up on the report at the time.

Experienced users may be able to catch this kind of bogus approval by independently verifying a contract address on Etherscan before signing, but that step remains a manual precaution rather than a built-in safeguard. For DeFi to achieve broader adoption, such checks likely need to become a streamlined, default part of the user experience rather than something left to individual vigilance. In the meantime, the practical takeaway is to maintain disciplined wallet and approval hygiene.

Badger
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.