Force DAO's xFORCE Bug Triggers a Community-Driven Sell-Off Before a White Hat Steps In
Force DAO's token holders effectively rekt themselves after a bug was discovered in the FORCE/xFORCE contract on April 4th, 2021. At 08:50 UTC, the project's Discord posted a notice explaining that a bug had been found and that an individual had, for safety reasons, removed all funds from the contract while coordinating with the team — advising the community to pause trading FORCE while the situation was addressed.

The warning arrived too late to prevent panic selling: by the time the message reached holders, the community had already dumped its FORCE tokens, leaving the person who intervened — a white hat hacker — holding a bag as FORCE's price collapsed roughly 90% within minutes, a drop driven by the community's own reaction rather than the white hat's actions.
On-chain records show the sequence of the intervention: 347,432,986 xFORCE were minted (transaction), which was used to withdraw 4,112 FORCE (transaction). That FORCE was then sold through 1inch (transaction), after which 14,833 FORCE was returned (transaction). Following the white hat's actions, additional opportunistic attackers — with notably poor operational security — moved in to scavenge what remained.
Ultimately the funds were returned, keeping Force DAO off the REKT leaderboard — though the episode raised the question of why the risk of exploiting the bug fell to an outside white hat rather than being caught by the project team itself. Observers also questioned what fallout, if any, this might have for BADGER's price.
The underlying flaw was a simple one. As researcher samczsun noted, the xFORCE vault contract failed to check the return value of a transferFrom call. The project's contract relied on the older MiniMeToken standard, which does not revert on a failed transfer but instead silently returns false when a transferFrom is attempted without sufficient approval or funds — a known quirk that should have been handled with a safe-transfer wrapper, or avoided altogether by using a more modern token standard for FORCE. Because of this gap, essentially anyone could have minted xFORCE and drained the contract, not just the white hat who ultimately did.
The incident also underscored a broader irony: even a token distributed via what was considered one of the smallest airdrops on record could end up costing recipients money once gas costs were factored in, given the price collapse. Commentary framed Force DAO as the case of the smallest airdrop followed by the easiest hack — a rare instance where the exploited flaw was patched up by a good-faith actor rather than an outright malicious one.

Get new scam files the moment we publish them — usually 2–3 emails a week.