A legacy MakerDAO auction-keeper contract has been exploited for over $500,000, with the exploit leveraging vulnerabilities dating back to Black Thursday in March 2020. A hacker targeted a historic auction-keeper that had won four 50-ETH lots during the liquidation crisis, ETH that had never been settled. The vulnerability stemmed from a missing access control on function 0x8804d1de in the keeper implementation. The stolen funds, totaling 200 ETH, were washed through Tornado Cash in 10-ETH lots. While this contract was no longer part of the current Sky system, the incident serves as a reminder that legacy contracts containing real value remain attractive targets for attackers.
Source: Read the original article

