Revoke.cash logo

BasketDAO Hack

Check if your address is affected.

27 Mar 2022
$1.2M stolen
Ethereum Logo

BasketDAO offered index tokens, such as its DeFi index BDI and its stablecoin index BMI, that bundled several tokens into one and earned yield through Yearn. The project wound down after an exploit in October 2021, but its contracts stayed live. In late March 2022, attackers found that two of its helper contracts, including one tied to its BMI index, could be tricked into moving tokens out of any wallet that had approved them. BasketDAO warned users about the first contract on 30 March 2022 and about the second a day later.

About $1.2M was stolen from wallets that had approved these contracts. BasketDAO asked everyone to revoke their approvals, told users not to approve any contracts on its website, and started taking its website offline while it checked its other contracts. The losses did not stop in 2022. In January 2024, security firm BlockSec warned that more than $107k had been drained through the BMI helper contract and again urged users to revoke their approvals.

In mid-2022, BasketDAO arranged for PieDAO to take over its community, and holders of the BDI index could swap into a PieDAO index between 29 June and 21 July 2022. Very little was migrated, and PieDAO later called the effort a failure. The vulnerable contracts are still on-chain and, as the 2024 drain shows, can still be abused. If you ever used BasketDAO, revoke any approvals to these contracts, even if you no longer hold its tokens.

Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.

Sources:x.com•x.com

Next time, revoke it automatically

Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.

See how Auto-Revoking works →
Get Ultimate
Back to Exploits