CryptoReal
CASE FILE — Sep 6, 2021

Second Exploit in a Month Drains $4M from DAO Maker via Reinitialized Contracts

DAO Maker has been exploited for a second time in under a month. Less than four weeks after an earlier $7M loss, the platform has now lost an additional $4M.

Credit: Mudit Gupta

The root cause was an unprotected init() function. An attacker exploited it to reinitialize four token contracts with malicious parameters, then called emergencyExit() on each to drain the funds.

The affected contracts and their corresponding withdrawal transactions:

0x6e70c88be1d5c2a4c0c8205764d01abe6a3d2e22emergencyExit drained 13.5M CAPS

0xd6c8dd834abeeefa7a663c1265ce840ca457b1ecemergencyExit drained 2.5M CPD, executed twice

0xdd571023d95ff6ce5716bf112ccb752e86212167emergencyExit drained 1.44M DERC

0xa43b89d5e7951d410585360f6808133e8b919289emergencyExit drained roughly 20.6M SHO

After draining and swapping those funds, the attacker attempted init() calls against two additional contracts.

Both had already been touched by a separate address whose history shows a repeated pattern of init() followed by emergencyExit(), pulling out millions in SHO plus additional amounts of ALPHR and LSS.

Curiously, that same address's last four transactions show the extracted tokens being sent back, followed by an ownership transfer — possibly an act of belated whitehat conduct, or the development team attempting damage control.

The attacker then liquidated each stolen token:

Ternoa: 13.5M CAPS swapped for 378,189 DAI via 1inch

Sums referenced in this case file

Coinspaid: 5M CPD swapped for 158,216 DAI via 1inch

DeRace: 1.44M DERC swapped for 997,833 DAI via 1inch

Showcase: 20.6M SHO swapped for 67,663 DAI via the MetaMask Swap Router

Token price impact, measured at the time of writing:

Ternoa (CAPS) fell as much as 45% before settling around -11%

CoinsPaid (CPD) fell as much as 60% before settling around -25%

DeRace (DERC) fell as much as 75% before settling around -25%

Showcase (SHO) remained down roughly 75%

All four tokens have recovered somewhat from their post-exploit lows, though not to the extent DAO Maker itself claimed.

DAO Maker's codebase is closed-source, raising the question of whether the vulnerability was found externally, or whether an insider was involved.

Mudit Gupta pointed out a discrepancy in DAO Maker's audit claims:

DaoMaker claimed that they had audits from 3 firms but looking at learn.daomaker.com/audits, 2 of the audits seem to be for unrelated contracts while the third one from @certik_io points to a dead link.

Certik has not yet responded to clarify.

Regardless of whether all three audits are legitimate, shifting blame onto auditors after being hacked is not a good look for any protocol. Security is ultimately the responsibility of the team building the product, not something that can be fully outsourced. That means getting every stage right — hiring, specification, code review, testing, fuzzing, formal verification, a bug bounty program, and incident response — with no room for shortcuts.

For DAO Maker, the damage from this second incident may already be done.

DAO Maker
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.