CryptoReal
CASE FILE — Oct 21, 2024

Compromised Vesting Contract Costs Tapioca DAO $4.4 Million on Arbitrum

Tapioca DAO, a lending protocol built on Arbitrum, lost approximately $4.4 million after an attacker gained control of private keys tied to its smart contracts. Part of the stolen value has since been clawed back, though the complete picture of the damage was still being assessed as the story developed.

Independent researcher 0xTeun raised the first public alarm that Tapioca was under active attack. The investigation that followed showed the attacker had abused an Emergency Rescue function present in one of the vesting contracts deployed by the Tapioca Deployer.

Using that opening, the attacker withdrew roughly 30 million TAP tokens and converted them into 591 ETH, a sale that dragged TAP's market price down by about 97%. Not content with that haul, the attacker then multicalled several additional addresses — among them the USDO stablecoin contract — and minted an extraordinary five quintillion USDO. Investigators traced the stolen assets as they were bridged from Arbitrum over to BNB Chain; at the time of reporting, the receiving address held around $4.4 million in stablecoins, mostly BSC-USD and USDC.

Roughly six hours after the attack began, Tapioca DAO issued its first statement, describing the incident not as a straightforward code exploit but as a "social engineering attack." Per the team's account, the attacker had seized ownership of the TAP token vesting contract and used that control to claim and sell the 30 million vested TAP tokens. Separately, ownership of the USDO stablecoin contract was also compromised, letting the attacker add an unauthorized minter, print USDO without limit, and drain the USDO/USDC liquidity pair. Tapioca's own tally of the loss — 591 ETH and 2.8 million USDC — lined up with the figures independent chain analysts had already produced.

On-chain references from the incident:

TAP Vesting Contract: 0x2997C5ddD3070A46E9938261ce0A16a237121cb0

Exploiter: 0x70285a11489bed93686410EBC727057CAfb8129D

Attack Transaction 1: 0x8cf8def40fa2beab66f46863478bea71ad8f4512003caf2fa639cc5a00550753

Sums referenced in this case file

Attack Transaction 2: 0x1abb8cf0b0af2ce19a30ce5103d51269d4600d9aeba045260feb588db89d76a4

Attack Transaction 3: 0x174c3deaf563be1bb6d873ba279421e8588acc888ef672bafd5efe7441aae74f

USDO Stablecoin Contract: 0xEB99062643cA5Ab880c077288345E0B14B297432

USDO Infinite Mint Exploit Transaction: 0x0bca43cfb5b14ea039f2b329cb6074383d54ed8240963014ccb6400befa5a4e3

Address receiving funds bridged from Arbitrum to BSC: 0x69d91e56ca80f2a4d7b808b59053ea5c5505ffe2

On-chain investigator ZachXBT then pointed to a possible pattern: the Tapioca incident may be connected to a recent cluster of attacks against projects including Nexera, Concentric, Masa, SpaceCatch, and others. The suspected common element across these cases is malware, potentially delivered through fake job postings — a method widely associated with North Korean state-sponsored hacking operations. The timing is notable, since the Tapioca exploit landed just a day after Radiant Capital was hit by an attack involving RAT malware.

In a surprising follow-up, Tapioca DAO announced via Discord that it had turned the tables on part of the theft: "We have hacked the hacker! Recovered 1000 ETH which is now safely in the DAO multisig. The 1000 ETH was DAO collateral within Big Bang Origins to mint USDO for USDO/USDC LP." Following that recovery, the DAO's treasury reportedly stood at $4.2 million. The team said a full post-mortem would follow and credited security groups Seal911 and EnigmaDarkLabs with assisting in the counter-operation. As Tapioca continued working through the aftermath, observers noted that the story was still unfolding.

Separately, opportunists moved quickly to impersonate Tapioca DAO's official channels and spread phishing links, prompting security firm Hacken to warn users against engaging with them. Whether the original breach traced back to a Tapioca team member falling for a social-engineering lure — such as a fabricated job offer, a tactic increasingly linked to malicious VS Code extensions and fake recruiting operations tied to North Korea — remains unconfirmed.

The episode adds to a growing list of incidents in which the point of failure was not flawed code but a compromised individual, underscoring that protocol security increasingly depends on vetting the humans behind the contracts as much as the contracts themselves.

Tapioca DAO
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.