logo

Hackerdao Incident Analysis

ID: 649658e7-4df5-59e4-8439-3f47594be4e7

STIX ID: report--649658e7-4df5-59e4-8439-3f47594be4e7

Feed Name: CertiK Blog

Threat Score
65/100

Date Published: 2022-11-16

Date Updated: 2026-06-11

...
...

On May 24, 2022 an attacker executed a flash-loan-based exploit against the Hackerdao token on BSC, abusing the token's special extra-fee behavior for transfers to a specific liquidity pool and the UniswapV2Pair "skim" mechanism to manipulate multiple pools and drain roughly 200 BNB (~$65K). The attacker took a DODO flashloan, performed swaps to alter pool balances, used skim calls to move tokens between pools which triggered extra fees, then swapped inflated tokens back to WBNB, repaid the loan and sent proceeds to Tornado Cash; several transaction and contract addresses are included. The report concludes the vulnerability could have been avoided with contract auditing and notes reduced project activity post-attack.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.