Millions Drained in ForceDAO Attacks, White Hat Returns Funds

ForceDAO suffered a major attack this morning. A white hat hacker has already returned the majority of the funds, but others appear to have made off with a tidy profit.

Personal Tokens Crash as Roll Suffers Nearly $6M Hack
Shutterstock cover by Makstorm

Key Takeaways

  • ForceDAO was drained of millions of dollars this morning after a white hat hacker discovered a bug in the smart contract’s code.
  • The white hat hacker successfully took 14.8 million FORCE tokens. Though they returned the funds, other attackers noticed the exploit and have sold their tokens for ETH.
  • FORCE briefly tanked 95% following the attack. It’s still deep in the red following the incident.

Share this article

Another multi-million dollar rug pull has hit the DeFi space. This weekend, ForceDAO is the victim. 

Disaster for ForceDAO 

ForceDAO has suffered a major attack. 

The exploit centers on a bug in the xFORCE contract’s code, which allowed anyone to call the “deposit” function regardless of whether they were holding FORCE tokens. That meant it was possible to mint xFORCE tokens from the contract without locking any tokens in the vault.

Anyone could then exchange these tokens for FORCE by calling the “withdraw” function in the contract. 

Several attackers took advantage of the exploit earlier this morning. One of them took about 14.8 million FORCE, which had a notional value of around $34 million at the time. They’ve since returned the funds to the pool.

However, four others drained another 6.75 million tokens and have begun exchanging their takings for ETH on various exchanges. As the white hat attacker had already found the exploit, liquidity plunged, which meant every subsequent attacker earned significantly less for their FORCE. 

Mudit Gupta, blockchain team lead at Polymath Network, detailed the attack in a tweetstorm.   

ForceDAO organized a highly anticipated airdrop yesterday, in which FORCE tokens were distributed to active Ethereum users. It was trading at around $2.30 earlier this morning but has since plummeted. At one point, it was down 95% and is now worth around $0.26

One of the black hat attackers used an address linked to the centralized exchange FTX, which gives some hope that the funds may be recovered. Most of the rest, though, has already been sold through the decentralized exchanges 1inch and SushiSwap. 

ForceDAO took to Twitter to confirm the attack. According to the team, a post-mortem will follow. 

This is a developing story and will be updated as further details surface.

Disclosure: At the time of writing, the author of this feature owned ETH and several other cryptocurrencies. They also had exposure to SUSHI in a cryptocurrency index. 

Share this article