MakerDAO keeper drain: 200 ETH out of Tornado Cash’s shadow and back into it in 31 minutes
PublicAML · On-chain investigation · 7 October 2026
On 6 October someone took 200 ETH, about $538,000, from a liquidation bot that had been sitting forgotten on Ethereum since 2020. It was not MakerDAO itself: the core contracts did what they were built to do. The bot belonged to a third party, and one of its functions could be called by anyone. We timed what happened around it. The attacker’s wallet received its first ether from Tornado Cash at 05:57 UTC, took the 200 ETH at 06:13 and had put all of it back into Tornado Cash by 06:28. Thirty-one minutes, start to finish.
200 ETH
taken at 06:13:11 UTC, 6 Oct 2026 (≈ $538,000)
31 min
from the wallet’s first ether to the last mixer deposit
20 × 10 ETH
into Tornado Cash, 06:19–06:28 UTC
0.07 ETH
left on the attacker’s wallet on 7 Oct
What was taken, and from whom
According to Defimon Alerts, which reported the incident, the target was an upgradeable keeper contract — a bot that bids in MakerDAO’s collateral auctions. In 2020 it won four ETH-A auctions, numbers 1457 to 1460, worth 50 WETH each, and never collected: the final step that hands the collateral to the winner was never called. For six years 200 WETH sat inside Maker’s auction contract, owed to a bot nobody was running.
The bot’s withdrawal function had no access check. Anyone could call it, finish the four old auctions on the bot’s behalf, pull the collateral through Maker’s own exit contract and name any address as the recipient. That is what happened. MakerDAO’s contracts were not broken and no user of the protocol lost anything; the loss is the bot owner’s.
Thirty-one minutes
The attacker’s wallet, 0x01EB957E5C7DcDDD60F3C875956cCc6fb9BdA5FA, did not exist before 05:57:23 UTC on 6 October, when 0.0978 ETH arrived from Tornado Cash’s 0.1 ETH pool — enough for gas and nothing else.
At 06:09 and 06:12 the wallet deployed two contracts. At 06:13:11 it called the second one, and in that single transaction the four auctions were settled, 200 WETH left Maker’s collateral adapter, was unwrapped, and 200 ETH landed on the attacker’s wallet.
Six minutes later the deposits began. Between 06:19:35 and 06:28:35 the wallet made twenty deposits of 10 ETH into Tornado Cash, one every half minute or so. That is all 200 ETH. What remains on the wallet is 0.07 ETH of unspent gas.
| When (UTC, 2026) | From | To | Amount | Tx |
|---|---|---|---|---|
| 6 Oct 05:57:23 | Tornado … pool) | 0x01EB95…BdA5FA | 0.0978 ETH the wallet’s first transaction | 0xd4c0b1…048ac6 |
| 6 Oct 06:12:11 | 0x01EB95…BdA5FA | 0xEc997d…321dcF | contract deployed second helper contract | 0x4a587a…ad1167 |
| 6 Oct 06:13:11 | 0xEc997d…321dcF | 0x01EB95…BdA5FA | 200 ETH four old auctions settled, 200 WETH unwrapped and paid out | 0xbb6940…f3a88c |
| 6 Oct 06:19:35 | 0x01EB95…BdA5FA | 0xd90e2f…24F31b | 10 ETH (1st of 20) first deposit, six minutes later | 0xb8ecff…ebefeb |
| 6 Oct 06:28:35 | 0x01EB95…BdA5FA | 0xd90e2f…24F31b | 10 ETH (20th) last deposit — all 200 ETH in the mixer | 0xf1db85…c8dcbf |
Why this one is worth a page
The amount is small. The pattern is not. A wallet whose first transaction is a withdrawal from a mixer, which then deploys a contract within minutes, is the same opening we saw before the Base vault drain, the Bonzo Lend exploit and the first Aztec drain. Here the whole operation fitted between two Tornado transactions, with a quarter of an hour in which nobody could have reacted.
It also used the 10 ETH pool rather than the 100 ETH one — twenty deposits where two would have done. Over the last quarter the thefts we traced almost always went through the 100 ETH pool. We do not know why this one did not.
And it is a reminder about old contracts. The same thing emptied Aztec’s retired rollups in June: code that was switched off years ago, still holding money, still callable.
What we did with the addresses
We have marked the attacker’s wallet and its two helper contracts as hack-related in our database. We did not mark the drained bot or any MakerDAO contract. There is no balance left to monitor. You can check any address on the address check page.
What this page does not say
It names nobody and does not say who controls any address. The mechanism and the attacker’s address were first published by Defimon Alerts; the timings, the Tornado funding and the deposits are ours, read from the chain on 7 October 2026. The dollar figure is the one reported on the day.
Check an address yourself
Free, no sign-up. Paste any address to see whether it is linked to this or any other incident:
Sources: Ethereum chain data via Blockscout, read on 7 October 2026; Defimon Alerts and press reports for the mechanism and the attacker’s address. This is an information resource about transactions between addresses, not financial or legal advice, and it names no individual as responsible for anything.