AdvertiseFee Deal Desk

Ethereum

Attacker Drains 200 ETH From Legacy Maker (MKR) Auction Keeper Tied to Black Thursday

An attacker drained 200 ETH, over $500,000, from a legacy MakerDAO auction-keeper tied to Black Thursday 2020 via a missing access control, per CertiK.

Be a creator
October 7, 2026, 11:49 PM UTC4 min read
AI SummaryAI
  • An unknown attacker drained 200 ETH, above $500,000, from a legacy MakerDAO auction-keeper.
  • The root cause was a missing access control on function 0x8804d1de.
  • Four lots of 50 ETH sat unsettled since the March 2020 Black Thursday liquidations.
  • The attacker routed the funds in 10-ETH tranches through Tornado Cash.
gate.com

200 ETH Leaves a Six-Year-Old Keeper Contract

An attacker removed 200 Ethereum (ETH), a sum the incident analysis values above $500,000, from a legacy auction-keeper contract built for MakerDAO, in a breach that reaches back six years to the Black Thursday crisis of March 2020. Security firm CertiK published its findings on Wednesday and pinned the root cause to a specific defect: a missing access control on the function indexed 0x8804d1de, inside the keeper implementation deployed at 0x68399ed8aa33C5b43F863EE6782de492006A5546. With that permission check absent, the attacker could invoke the function and extract four lots of 50 ETH that had sat unsettled in the contract since 2020. The selector and implementation address are now public, which lets any security researcher reproduce the finding independently. Against the multi-million-dollar breaches that dominate the exploit category this year, the figure is small, but the provenance of the funds is what makes the case unusual. An auction-keeper is an automated contract that bids into a protocol's collateral auctions on its operator's behalf, and this one collected its Ethereum (ETH) during the liquidation wave that tore through the DAO when Ethereum collapsed in March 2020. On-chain records show the proceeds moving out in 10-ETH tranches through Tornado Cash, the mixer that severs the visible path of stolen assets, from an address Etherscan lists as the recipient. The report does not name the attacker. The Maker (MKR) price, carried by the protocol's governance token, sits 10.4% lower across the past 24 hours, while the cache the attacker took was denominated entirely in ETH.

Black Thursday describes the March 2020 session when ETH collapsed faster than MakerDAO's liquidation machinery could process it, and auctions that would normally draw competition cleared without a single rival bid. This auction-keeper was among the first contracts to win ETH from the system on those zero-bid terms, taking collateral while the protocol's auctions undershot any reasonable market price. At those terms, value left the protocol for effectively nothing, which is how a contract built to serve auctions ended the crisis holding Ethereum (ETH) it never converted. Four of its 50-ETH lots were never settled, and they stayed on the contract's books through every market cycle since. Those 200 ETH are exactly what the missing access control placed within reach. The contract sits outside the current Sky ecosystem, the rebranded continuation of the Maker protocol, and it has not been central to that system for half a decade. The rebrand to Sky shifted attention and treasury to new infrastructure, leaving components like this one outside the perimeter of routine review. That dormancy is the uncomfortable part of the case: a module sidelined since 2020 still carried real value, and half a decade of inactivity did not reduce the balance to dust. For Sky's present architecture, the incident is operationally inert, but it sharpens an audit question the industry tends to postpone: whether orphaned contracts from earlier generations should be emptied or formally wound down rather than left funded on mainnet. CertiK's post-mortem stops at the diagnosis, and no patch, pause or clawback accompanies it.

Tornado Cash Routing Complicates Recovery

The on-chain evidence makes the character of this theft clear: the attacker needed no novel technique, only an unguarded function on a contract whose funded lots had been visible on-chain for six years. The 10-ETH tranches into Tornado Cash point to deliberate routing rather than a hurried exit, and once value enters the mixer, practical recovery effectively ends. For Maker (MKR) holders the exposure is reputational rather than balance-sheet, since the protocol's present collateral engine was never in the path of the attack. What remains open is the state of the breach point itself: neither the post-mortem nor any team statement describes a pause, a patch or a recovery effort, so that state is unreported.

COINOTAG's editorial and research desk.

AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.