Second Exploit in a Month Drains $4M from DAO Maker via Reinitialized Contracts
DAO Maker has been exploited for a second time in under a month. Less than four weeks after an earlier $7M loss, the platform has now lost an additional $4M.
Credit: Mudit Gupta

The root cause was an unprotected init() function. An attacker exploited it to reinitialize four token contracts with malicious parameters, then called emergencyExit() on each to drain the funds.
The affected contracts and their corresponding withdrawal transactions:
0x6e70c88be1d5c2a4c0c8205764d01abe6a3d2e22 — emergencyExit drained 13.5M CAPS
0xd6c8dd834abeeefa7a663c1265ce840ca457b1ec — emergencyExit drained 2.5M CPD, executed twice
0xdd571023d95ff6ce5716bf112ccb752e86212167 — emergencyExit drained 1.44M DERC
0xa43b89d5e7951d410585360f6808133e8b919289 — emergencyExit drained roughly 20.6M SHO
After draining and swapping those funds, the attacker attempted init() calls against two additional contracts.
Both had already been touched by a separate address whose history shows a repeated pattern of init() followed by emergencyExit(), pulling out millions in SHO plus additional amounts of ALPHR and LSS.
Curiously, that same address's last four transactions show the extracted tokens being sent back, followed by an ownership transfer — possibly an act of belated whitehat conduct, or the development team attempting damage control.
The attacker then liquidated each stolen token:
Ternoa: 13.5M CAPS swapped for 378,189 DAI via 1inch
Coinspaid: 5M CPD swapped for 158,216 DAI via 1inch
DeRace: 1.44M DERC swapped for 997,833 DAI via 1inch
Showcase: 20.6M SHO swapped for 67,663 DAI via the MetaMask Swap Router
Token price impact, measured at the time of writing:
Ternoa (CAPS) fell as much as 45% before settling around -11%
CoinsPaid (CPD) fell as much as 60% before settling around -25%
DeRace (DERC) fell as much as 75% before settling around -25%
Showcase (SHO) remained down roughly 75%

All four tokens have recovered somewhat from their post-exploit lows, though not to the extent DAO Maker itself claimed.
DAO Maker's codebase is closed-source, raising the question of whether the vulnerability was found externally, or whether an insider was involved.
Mudit Gupta pointed out a discrepancy in DAO Maker's audit claims:
DaoMaker claimed that they had audits from 3 firms but looking at learn.daomaker.com/audits, 2 of the audits seem to be for unrelated contracts while the third one from @certik_io points to a dead link.
Certik has not yet responded to clarify.
Regardless of whether all three audits are legitimate, shifting blame onto auditors after being hacked is not a good look for any protocol. Security is ultimately the responsibility of the team building the product, not something that can be fully outsourced. That means getting every stage right — hiring, specification, code review, testing, fuzzing, formal verification, a bug bounty program, and incident response — with no room for shortcuts.
For DAO Maker, the damage from this second incident may already be done.
Get new scam files the moment we publish them — usually 2–3 emails a week.