BadgerDAO Frontend Hack
Check if your address is affected.
BadgerDAO is a DeFi project focused on bringing Bitcoin into Ethereum's DeFi ecosystem, mainly through vaults that earn yield on wrapped Bitcoin. In November 2021, attackers gained control over part of Badger's official website, most likely through its Cloudflare account, and started injecting malicious code into it. When users made normal transactions on the site, the code slipped in extra approval requests that gave the attackers' wallet unlimited access to their tokens. The code only appeared now and then and mostly targeted larger wallets, which helped it go unnoticed for weeks.
On 2 December 2021, the attackers used these approvals to drain over $120M from users, making it one of the largest DeFi exploits at the time. Most of the stolen funds were vault tokens, which were quickly cashed out and bridged back to the Bitcoin network. Badger paused most of its vaults within hours, which blocked further thefts of vault tokens, although other approved tokens could still be taken. Stolen vault tokens worth about $9.2M were still recoverable and were later returned to the wallets they came from, leaving around $111M lost. The DAO also set up a restitution plan to repay other losses over time.
The malicious approvals were given to a wallet controlled by the attackers, not to a Badger contract, so they stay dangerous for as long as they exist. If you used the Badger website in November or early December 2021, check your wallet for approvals to the attacker's address and revoke them. This incident is also a reminder that even the official website of a trusted project can be compromised, so always check which address you are approving before you confirm a transaction.
Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.
Next time, revoke it automatically
Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.
See how Auto-Revoking works →