MakerDAO Keeper Exploited for $538,000 in WETH
A dormant liquidation keeper linked to MakerDAO was exploited, resulting in a loss of approximately $538,000 worth of Wrapped Ether (WETH). The incident, reported by Defimon Alerts, involved an unprotected drain function in a third-party keeper proxy contract. The attacker exploited an access-control issue, allowing them to withdraw 200 WETH that had remained locked in MakerDAO’s ETH-A Flipper since 2020.
The affected keeper had previously won four ETH-A liquidation auctions in 2020, leaving the collateral untouched until the attacker triggered the keeper’s withdrawal logic. Defimon Alerts noted that the drain function was not protected by MakerDAO’s ds-auth access-control mechanism, making it accessible to any caller. The attacker then transferred the WETH to a specified recipient and converted it into ETH.
Despite the exploit, MakerDAO’s core contracts remained uncompromised. Defimon Alerts clarified that the vulnerability was specific to the keeper’s unprotected exit function, not the core system. The transaction, recorded on Etherscan, confirmed the exploit’s success on October 6, 2026, at 06:13:11 UTC. The attacker’s address was reportedly funded through Tornado Cash, though further details about their identity remain unclear.
The incident highlights the risks associated with dormant assets in crypto systems. It follows another recent exploit involving digital assets, underscoring the importance of robust security measures in decentralized finance (DeFi).