Key Highlights
- A dormant MakerDAO ETH-A liquidation keeper was drained of about $538,000 in 200 WETH.
- Defimon Alerts said the exploit involved an unprotected drain function in a third-party keeper proxy.
- The keeper had won four ETH-A liquidation auctions in 2020, leaving 200 WETH locked in MakerDAO’s ETH-A Flipper.
A dormant MakerDAO ETH-A liquidation keeper was drained of 200 WETH worth about $538,000 after an attacker exploited an access-control issue in the keeper’s proxy contract, according to Defimon Alerts.
In a security alert post on X on Tuesday, Defimon Alerts reported that the attacker called a drain function not protected by MakerDAO’s ds-auth access-control mechanism.
The keeper won four ETH-A liquidation auctions in 2020, and the resulting collateral remained locked in MakerDAO’s ETH-A Flipper until the attacker triggered the keeper’s withdrawal logic.
Unprotected function allowed the drain
Defimon Alerts said the affected keeper was an upgradeable proxy at 0x9c05…8273, with an implementation at 0x6839…5546. The implementation reportedly contained a drain routine with the selector 0x8804d1de. According to the security alert, the function was not protected by ds-auth. The contract’s owner was listed as 0xadc374e7, while its authority was set to 0x0.
Defimon Alerts said this meant any caller could invoke the drain function.
The routine then called Flipper.deal() for the keeper’s old liquidation auctions, causing the collateral to be transferred to the keeper. It subsequently used GemJoin.exit() to withdraw the 200 WETH to a recipient supplied by the attacker before converting the WETH into ETH.
200 WETH was left from 2020 auctions
The affected keeper had previously won four ETH-A liquidation auctions, numbered 1457 through 1460, with each auction involving 50 WETH. The keeper never called deal() after winning those auctions, leaving a combined 200 WETH of collateral locked in the ETH-A Flipper.
That dormant balance remained in the system until the attacker discovered that the keeper’s drain routine could be called without authorization. The attack therefore did not require a new MakerDAO liquidation. Instead, the attacker used the dormant keeper and its previously won auctions to withdraw the collateral.
MakerDAO core contracts were not breached
The incident has been described as an access-control failure in an old keeper component rather than a compromise of MakerDAO’s core contracts.
Defimon Alerts said, “MakerDAO core (Vat/Flipper/GemJoin) behaved as designed; the flaw is the third-party keeper’s unprotected exit function.”
Cryptoiz Research, which shared an analysis of the incident on X, similarly said the loss “did not occur because the MakerDAO core was successfully breached.” According to Cryptoiz Research, the funds had remained locked since 2020 in an old keeper proxy used by MakerDAO’s liquidation system.
The account said the attacker reactivated the four old auctions, moved the collateral through Vat. flux, extracted it through GemJoin, and ultimately converted the 200 WETH into ETH.
Cryptoiz Research said the issue was an old component with an authentication gap, meaning anyone could call the unprotected drain function.
Etherscan shows successful exploit transaction
On-chain data from Etherscan shows that the exploit transaction was successful.
The transaction hash is:
0xbb6940f7c2a1e68cafbae7bb9b94d09af9af06ec3a114f6996f2cab993f3a88c
According to the Etherscan transaction page, the transaction was included in Ethereum block 26,131,471 and was timestamped October 6, 2026, at 06:13:11 UTC.

Etherscan transaction page of October 06 at 06:13:11 UTC | Source: Etherscan
The transaction was sent from 0x01EB957e5C7DcDDD60F3C875956cCc6fB9bDa5FA, matching the attacker address identified by Defimon Alerts.
Etherscan also shows that the transaction interacted with 0xEc997d2aD033277913d600227735368E8321dcf and created the contract 0xF09A13072Ed939b79Bc25b66aa3a836ea6dcc170.
The on-chain record supports the reported transaction execution, while the details about the vulnerability and its connection to the dormant keeper come from Defimon Alerts’ security analysis.
Defimon Alerts identifies Tornado-funded EOA
Defimon Alerts said the attacker used a fresh EOA funded through Tornado Cash before carrying out the transaction. However, the available information does not establish who controls the address or independently confirm the identity of the attacker.
Following the alert, Ana Traces ETH questioned whether the keeper proxy was uninitialized or simply misconfigured. “Before the label goes anywhere, I want the deployer funding path and whether that proxy was actually uninitialized or just misconfigured. Two different stories,” Ana Traces ETH said in a reply.
Ana Traces ETH said the proxy’s deployment history and configuration could help clarify how the address was compromised.
Defimon Alerts has not provided further details in the information shared about how the attacker located the dormant keeper or whether the address had been targeted previously.
Recent crypto exploits highlight asset recovery risks
The MakerDAO incident follows another recent crypto exploit involving digital assets.
In September, Magic Eden reported that 23,155 NFTs worth more than $5.7 million were moved to safety, while about 660 WETH reportedly remained at risk following the Limit Break exploit. Yuga Labs’ Quit Rescues 23,155 NFTs reported on the asset recovery effort.
The Limit Break incident involved a different vulnerability and asset, so the two cases are not otherwise connected.
Also Read: Crypto ‘Godfather’ Adam Iza Gets 78 Months for $37M Meta Fraud and Corrupt Deputy Scheme
