- Amount Lost: $72,693.00
- Funds Returned: $0.00
- Category: NFT,Token
- Date: 2023-6-30
Quick Summary
AzukiDAO, an Ethereum-based DAO project, was exploited in a replay attack resulting in a loss of 72,693 $USD.
**
**
Details of the Exploit
AzukiDAO's governance token contract (Bean) was exploited due to a contract vulnerability that was not properly checking the signatureClaimed variable, leading to replay attacks. Two attackers exploited this vulnerability and made a combined profit of approximately 35 ETH. The exploit has been halted with the contract currently in a paused state. The funds are currently remaining in the attacker's address as ETH.
Block Data Reference
Attacker Address:
https://etherscan.io/address/0x85d231c204b82915c909a05847cca8557164c75e
Malicious Transaction Example:
https://etherscan.io/tx/0x4c50c1da8a25bcaf7c47661423f435a339c8dd3ce8f0e8e1c3a21dcc52e84acc
Proof Links:
