BadgerDAO hack — December 2021
Incident facts
| Date of incident | |
|---|---|
| Target type | DAO or treasury |
| Loss | $120,000,000Price at time of incident |
| Method | Supply chain or frontend compromiseMalicious script injected through a compromised Cloudflare API key added unlimited spend approvals |
| Chains | Ethereum |
| Outcome | Unresolved |
What happened
BadgerDAO lost about $120m of user funds in an attack disclosed on 2 December 2021. The protocol's contracts were never exploited.
An attacker obtained an API key for BadgerDAO's Cloudflare account — created without the knowledge of the engineering team — and used it to inject a script into the site's front end. The script was served intermittently and to a subset of visitors, which delayed detection. When a user carried out an ordinary transaction, the script added an unlimited spend approval for the attacker's address alongside it.
Around 500 wallets signed those approvals. The attacker then drained them at leisure. BadgerDAO eventually halted the theft by freezing calls to transferFrom.
The incident is the clearest illustration in the registry of a category that contract audits do not cover: the interface between a user and a correct contract. Nothing the user signed was invalid, and nothing the protocol had deployed was flawed.
Sources
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "BadgerDAO hack — December 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/badgerdaohttps://itokenly.com/hacks/badgerdaoPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.