MakerDAO keeper drain: 200 ETH out of Tornado Cash’s shadow and back into it in 31 minutes

PublicAML · On-chain investigation · 7 October 2026

On 6 October someone took 200 ETH, about $538,000, from a liquidation bot that had been sitting forgotten on Ethereum since 2020. It was not MakerDAO itself: the core contracts did what they were built to do. The bot belonged to a third party, and one of its functions could be called by anyone. We timed what happened around it. The attacker’s wallet received its first ether from Tornado Cash at 05:57 UTC, took the 200 ETH at 06:13 and had put all of it back into Tornado Cash by 06:28. Thirty-one minutes, start to finish.

200 ETH

taken at 06:13:11 UTC, 6 Oct 2026 (≈ $538,000)

31 min

from the wallet’s first ether to the last mixer deposit

20 × 10 ETH

into Tornado Cash, 06:19–06:28 UTC

0.07 ETH

left on the attacker’s wallet on 7 Oct

What was taken, and from whom

According to Defimon Alerts, which reported the incident, the target was an upgradeable keeper contract — a bot that bids in MakerDAO’s collateral auctions. In 2020 it won four ETH-A auctions, numbers 1457 to 1460, worth 50 WETH each, and never collected: the final step that hands the collateral to the winner was never called. For six years 200 WETH sat inside Maker’s auction contract, owed to a bot nobody was running.

The bot’s withdrawal function had no access check. Anyone could call it, finish the four old auctions on the bot’s behalf, pull the collateral through Maker’s own exit contract and name any address as the recipient. That is what happened. MakerDAO’s contracts were not broken and no user of the protocol lost anything; the loss is the bot owner’s.

Thirty-one minutes

The attacker’s wallet, 0x01EB957E5C7DcDDD60F3C875956cCc6fb9BdA5FA, did not exist before 05:57:23 UTC on 6 October, when 0.0978 ETH arrived from Tornado Cash’s 0.1 ETH pool — enough for gas and nothing else.

At 06:09 and 06:12 the wallet deployed two contracts. At 06:13:11 it called the second one, and in that single transaction the four auctions were settled, 200 WETH left Maker’s collateral adapter, was unwrapped, and 200 ETH landed on the attacker’s wallet.

Six minutes later the deposits began. Between 06:19:35 and 06:28:35 the wallet made twenty deposits of 10 ETH into Tornado Cash, one every half minute or so. That is all 200 ETH. What remains on the wallet is 0.07 ETH of unspent gas.

When (UTC, 2026)FromToAmountTx
6 Oct 05:57:23Tornado … pool)0x01EB95…BdA5FA0.0978 ETH
the wallet’s first transaction
0xd4c0b1…048ac6
6 Oct 06:12:110x01EB95…BdA5FA0xEc997d…321dcFcontract deployed
second helper contract
0x4a587a…ad1167
6 Oct 06:13:110xEc997d…321dcF0x01EB95…BdA5FA200 ETH
four old auctions settled, 200 WETH unwrapped and paid out
0xbb6940…f3a88c
6 Oct 06:19:350x01EB95…BdA5FA0xd90e2f…24F31b10 ETH (1st of 20)
first deposit, six minutes later
0xb8ecff…ebefeb
6 Oct 06:28:350x01EB95…BdA5FA0xd90e2f…24F31b10 ETH (20th)
last deposit — all 200 ETH in the mixer
0xf1db85…c8dcbf

Why this one is worth a page

The amount is small. The pattern is not. A wallet whose first transaction is a withdrawal from a mixer, which then deploys a contract within minutes, is the same opening we saw before the Base vault drain, the Bonzo Lend exploit and the first Aztec drain. Here the whole operation fitted between two Tornado transactions, with a quarter of an hour in which nobody could have reacted.

It also used the 10 ETH pool rather than the 100 ETH one — twenty deposits where two would have done. Over the last quarter the thefts we traced almost always went through the 100 ETH pool. We do not know why this one did not.

And it is a reminder about old contracts. The same thing emptied Aztec’s retired rollups in June: code that was switched off years ago, still holding money, still callable.

What we did with the addresses

We have marked the attacker’s wallet and its two helper contracts as hack-related in our database. We did not mark the drained bot or any MakerDAO contract. There is no balance left to monitor. You can check any address on the address check page.

What this page does not say

It names nobody and does not say who controls any address. The mechanism and the attacker’s address were first published by Defimon Alerts; the timings, the Tornado funding and the deposits are ours, read from the chain on 7 October 2026. The dollar figure is the one reported on the day.

Check an address yourself

Free, no sign-up. Paste any address to see whether it is linked to this or any other incident:

Sources: Ethereum chain data via Blockscout, read on 7 October 2026; Defimon Alerts and press reports for the mechanism and the attacker’s address. This is an information resource about transactions between addresses, not financial or legal advice, and it names no individual as responsible for anything.