TempleDAO (STAX Liquidity Vault) hack — October 2022
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | October 11, 2022 |
| Target type | DAO or treasury |
| Loss | $2,300,000Published estimates range $2,300,000 to $2,400,000Price at time of incident |
| Method | Access control flawThe StaxLPStaking contract on Ethereum exposed a migrateStake() function intended to be callable only by a designated migrator contract during a planned upgrade. The function carried no access-control check and did not validate its oldStaking argument, so any caller could supply a contract they controlled together with an arbitrary amount and have the vault release the corresponding staked xLP position to them. |
| Chains | Ethereum |
| Outcome | Unresolved |
What happened
On 11 October 2022 an attacker emptied the STAX Liquidity Vault, a liquidity-staking product associated with TempleDAO, by calling a function on its staking contract that had been left open to the public.
The StaxLPStaking contract on Ethereum exposed a migrateStake() function meant to be called only by a designated migrator contract during a planned upgrade. It carried no access-control modifier and did not validate the oldStaking address passed to it. SolidityScan's analysis of the deployed contract found that any caller could supply a contract they controlled as oldStaking together with an arbitrary amount, and the vault would release the corresponding staked position to the caller. The call was repeated across multiple staker accounts.
Crypto Briefing, relying on PeckShield's on-chain accounting, put the loss at 1,831 ETH, about $2.3 million, made up of 321,154 xLP tokens that the attacker swapped for roughly 1.3 million FRAX and 1.4 million TEMPLE, with the TEMPLE then also converted to FRAX. SolidityScan's write-up gives a higher figure of $2.4 million. The two were never reconciled, and no audited accounting of the loss was published.
STAX disabled its front end and told users not to deposit further, saying the exploiter could do no further harm. TempleDAO said its own vault contracts shared no code with STAX and remained secure. A white-hat bounty was announced and the project said it was coordinating with Binance over an account the attacker appeared to have used. No return of funds, identification of the attacker, or charges have been reported.
Sources
- Crypto BriefingSecondary · retrieved 2026-08-01
- SolidityScanSecondary · retrieved 2026-08-01
- Lancer ShieldAggregator · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "TempleDAO (STAX Liquidity Vault) hack — October 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/templedaohttps://itokenly.com/hacks/templedaoPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.