Curio DAO hack — March 2024
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | March 25, 2024 |
| Target type | DAO or treasury |
| Loss | $177,744Published estimates range $177,744 to $16,000,000Price at time of incident |
| Method | Access control flawA voting-power privilege check in Curio's MakerDAO-derived governance contracts could be satisfied with a trivially small holding of the Curio Governance Token. The attacker used the plot function to install a contract of their own as the system's executable library and reached it via delegatecall, which executes external code with the calling contract's identity, permissions and storage, allowing an unauthorised mint of roughly one billion CGT which was then used to drain the pools where CGT traded. |
| Chains | Ethereum, BNB Chain |
| Outcome | Unresolved |
What happened
On 23 March 2024 an attacker exploited an access control flaw in Curio's governance contracts, which were derived from MakerDAO's code, across Ethereum and BNB Chain.
The check that gated privileged actions measured the caller's voting power but could be satisfied with a very small holding of the Curio Governance Token. Holding only a token amount of CGT, the attacker used the plot function to install a contract of their own as the system's executable library, then reached it through a delegatecall, which runs external code with the calling contract's identity, permissions and storage. From that position they minted roughly one billion CGT the protocol had never authorised, and used part of it to drain the pools where CGT traded, afterwards swapping and bridging the proceeds to make them harder to freeze.
The figure attached to this incident in most coverage is $16 million. Neither Halborn nor The Crypto Times sets out how it is calculated; it is consistent with pricing the roughly one billion newly minted CGT at the token's market rate before the attack, but no consulted source states that derivation. Merkle Science's flow-of-funds analysis put documented losses at about $140,498 on Ethereum and about $37,246 on BNB Chain, roughly $178,000 combined, and reported that the attacker's proceeds sat idle with no movement of funds observed. This entry records the on-chain figure as the amount taken and the $16 million as the upper bound, because no published methodology supports the larger number.
Curio announced a recovery plan two days later: a replacement CGT 2.0 token intended to make original holders whole, compensation for liquidity providers in USDC and USDT across four stages of 90 days each, and a white-hat reward for help recovering assets. Curio said its Polkadot and Curio Chain contracts were unaffected.
Sources
- Merkle ScienceSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
- The Crypto TimesSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Curio DAO hack — March 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/curio-daohttps://itokenly.com/hacks/curio-daoPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.