Refreshed 1h ago· updates every 6h

BadgerDAO (2021) — Crypto Hack

Partially Recovered
Dec 2, 2021·
Ethereum
Amount Stolen
$120.0M
~2,100 BTC + various tokens
Recovered
$9.0M
8% of stolen funds

Malicious script injected into BadgerDAO's Cloudflare-hosted frontend intercepted wallet approvals and redirected user funds.

Summary

Malicious script injected into BadgerDAO's Cloudflare-hosted frontend intercepted wallet approvals and redirected user funds.

How It Was Compromised — DeFi via Frontend Injection

DeFiFrontend Injection

Attackers injected a malicious Cloudflare Worker script into BadgerDAO's frontend that prompted users to approve additional token transfers to attacker-controlled addresses. The script was active for several weeks before detection. Users who interacted with the compromised frontend unknowingly granted the attacker unlimited token allowances.

Fund Flow & Laundering Analysis

Stolen BTC and ETH moved through multiple wallets. Significant BTC moved to renBTC bridge and then dispersed. Some ETH routed through Tornado Cash. Blockchain analytics firms (Chainalysis, TRM Labs) tracked portions to known Lazarus Group-associated wallets, though attribution remains uncertain.

Related Incidents

For educational and transparency purposes only. Not financial advice. Data compiled from public sources and may contain approximations.