Revoke.cash logo

BasketDAO Peripheral Exploit

Check if your address is affected.

24 Oct 2021
$343k stolen
Ethereum Logo

BasketDAO was a DeFi protocol that offered basket tokens such as BDI, a DeFi index token that bundles several DeFi tokens into one. Next to the main BDI contract, it ran separate add-on contracts that let users mint and burn BDI with a delay. In October 2021, the team was warned that one of these add-ons, the DelayedBDIBurner, had a serious flaw. It let anyone move BDI tokens out of wallets that had approved the contract, not just out of the contract itself.

The attacker used the flaw to take BDI worth about $343k. At first the team thought only tokens held by the contract were at risk, so after clawing the stolen tokens back with an emergency fix, it sent them back to the wallets they came from. Because the approvals were still active, the attacker simply took the tokens again, sold them and moved the proceeds through Tornado Cash. BasketDAO later partly compensated those affected by giving up about $118k in fees from its treasury.

In response, BasketDAO disabled its delayed mint and burn modules and said it would remove the fees for minting and burning directly on the main BDI contract, which was not affected. The project began winding down soon afterwards, and in December 2021 PieDAO proposed taking over its remaining products. The team did not announce a fix for the DelayedBDIBurner itself, so anyone who still has an approval for it should revoke it as a precaution. Revoking protects what is still in your wallet but does not recover lost tokens.

Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.

Next time, revoke it automatically

Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.

See how Auto-Revoking works →
Get Ultimate
Back to Exploits