T
iTokenly

Tapioca DAO hack — October 2024

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedOctober 18, 2024
Target typeLending protocol
Loss$4,650,000Published estimates range $4,400,000 to $4,750,000Price at time of incident
Recovered$2,650,000
MethodSocial engineeringA core contributor with admin roles on live contracts was approached on LinkedIn and Telegram by an attacker using a fabricated recruiter identity and a fake job offer, and was induced to run a malicious file that installed credential-stealing code and exposed his private keys. Using those roles the attacker added a minter to the USDO stablecoin contract, issued a very large unbacked supply and swapped it for USDC out of the USDO liquidity pools, and separately pulled TAP tokens out of the vesting contract using an emergency rescue function and sold them for ETH. The DAO's post-mortem states the contributor had repeatedly been instructed to transfer admin roles to the DAO's 4-of-7 multisig and had not done so.
ChainsArbitrum, Ethereum
Attributed toLazarus GroupSuspected
OutcomePartially recovered

What happened

Tapioca DAO ran an omnichain money market and the USDO stablecoin, deployed principally on Arbitrum with contracts also on Ethereum. At 10:09 UTC on 18 October 2024 an attacker obtained the private keys of a core contributor who still held admin roles on live contracts.

According to the DAO's post-mortem, the contributor was approached through LinkedIn and Telegram by an attacker using a fabricated recruiter identity and a fake job offer, and was persuaded to run a malicious file that installed credential-stealing code and exposed his keys. The post-mortem states he had repeatedly been told to move the admin roles to the DAO's 4-of-7 multisig and had not done so. With those roles, the attacker added a minter to the USDO contract, issued a very large unbacked supply and swapped it for USDC out of the USDO liquidity pools, and separately withdrew TAP tokens from the vesting contract through an emergency rescue function and sold them for ETH. TAP fell about 96 percent.

Figures differ. The DAO's post-mortem puts the loss at roughly $4.65 million, about 605 ETH and 3.1 million USDC. Halborn reports about $4.4 million, 591 ETH and 2.8 million USDC; other coverage cites $4.7 million. Part of the proceeds was bridged to BNB Chain via Stargate.

Tapioca offered the attacker a $1 million USDT white-hat bounty, which it revoked on 22 October. Its post-mortem records about $2.65 million retrieved through a counter-exploit run with EnigmaDark Labs, plus roughly $700,000 recovered from Uniswap v3 pools. The contributor was terminated and his and the Pearl Labs founders' contributor token allocations were revoked. The post-mortem attributes the intrusion to a North Korean group, based on an identification by SEAL911; Halborn separately notes the fake-recruiter lure is a method commonly associated with the Lazarus Group. Neither amounts to a formal attribution.

Law enforcement

The DAO says it worked with SEAL 911, Binance and legal counsel. No charges, indictment or formal government attribution has been identified.

Sources

  1. Tapioca DAOPrimary · retrieved 2026-08-01
  2. HalbornSecondary · retrieved 2026-08-01
  3. Riva NorthSecondary · retrieved 2026-08-01
  4. BanklessSecondary · retrieved 2026-08-01

Official post-mortem: https://paragraph.com/@tapiocada0/10-18-24-incident-post-mortem

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Tapioca DAO hack — October 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/tapioca-dao
https://itokenly.com/hacks/tapioca-dao

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.