Maker Vault Phisher Walks Away With $55.47 Million in DAI
A crypto holder lost $55.47 million in DAI on August 20, 2024, after falling for a phishing scheme that targeted their Maker vault, according to on-chain investigator ZachXBT, who first flagged the unusual outflow.
The victim appears to have noticed something was wrong and attempted to move the funds to safety, but by then control had already passed to the attacker, and the withdrawal attempt failed.

Drawing on reporting from ZachXBT, CertiK, The Block, and Lookonchain, the mechanics of the exploit can be reconstructed as follows: the victim signed a malicious transaction that handed the attacker control of their externally owned account (EOA). Using that access, the attacker transferred ownership of the victim's DSProxy — a smart contract that bundles multiple calls into a single transaction — to an address they controlled. That transfer allowed the attacker to change the owner address on the victim's Maker Vault and withdraw 55,473,618 DAI directly into their own wallet.
The addresses involved:
Victim's address: 0xf2B889437F243396b29E829908b5d8ebE2e13048
Phishing address: 0x0000db5c8B030ae20308ac975898E09741e70000
Attacker's withdrawal address: 0x5D4b2A02c59197eB2cAe95A6Df9fE27af60459d4
Main heist transaction: 0xf70042bf3ae7c22f0680f8afa078c38989ed475dfbe5c8d8f30a50d4d2f45dc4

Lookonchain reported that the attacker moved quickly to launder the proceeds: by the time of its report, 27.5 million of the stolen DAI had already been swapped for 10,625 ETH.
The incident adds to an already heavy phishing toll for 2024 — CertiK has put total losses from such attacks at nearly $498 million for the first half of the year alone. Jingyi Guo, an analyst at Blocksec, told The Block that the victim's repeated failed attempts to invoke the DSProxy after ownership had already changed hands point strongly to an unwitting phishing-transaction signature as the root cause.
The episode is a reminder of how little room for error exists once a wallet holds a position of this size: a single signature on an unfamiliar transaction was enough to hand over tens of millions of dollars. Standard precautions — multi-factor authentication, hardware wallets, and careful scrutiny of any transaction before signing — remain the primary defense against this class of attack.
Get new scam files the moment we publish them — usually 2–3 emails a week.