200 WETH Stolen from Dormant MakerDAO Liquidation Bot
A recent security incident has resulted in the theft of 200 WETH (approximately $538,000) from a dormant MakerDAO liquidation bot proxy. According to Defimon Alerts, the funds were withdrawn on October 6 by a new address linked to Tornado Cash.
The compromised proxy contract had previously won four ETH-A liquidation auctions in 2020 (Auctions #1457 to #1460), each worth 50 WETH. However, the bot never executed the deal() function, leaving the collateral locked in the Flipper contract.
The vulnerability stemmed from an unprotected withdrawal function in the implementation contract. This allowed any caller to trigger the function, first calling deal() on the old auctions, then transferring the collateral to the keeper via Vat.flux, and finally using GemJoin.exit to send the 200 WETH to the caller-specified address and unwrap them into ETH.
MakerDAO's core contracts functioned as intended, but the issue originated from a third-party bot’s permissionless exit function. The incident highlights the risks associated with unsecured smart contract functions in decentralized finance (DeFi) systems.