BadgerDAO front-end attack
A DeFi protocol whose users lost about $120M on December 2, 2021 — not via a smart-contract bug but a front-end attack: a compromised Cloudflare API key let attackers inject a script that tricked users into approving malicious token allowances, then drained their wallets.
Also known as: BadgerDAO, Badger DAO, BADGER
Summary
BadgerDAO is a DeFi protocol focused on tokenized Bitcoin. On December 2, 2021, attackers stole about $120 million from its users — one of the largest DeFi losses to that point — without exploiting the protocol's smart contracts. [1][2]
Method
The attackers obtained a compromised Cloudflare API key for the project and used it to inject a malicious script into the BadgerDAO website. When users transacted, the script inserted requests for unlimited token spending approvals to an attacker-controlled address; once granted, the attacker drained tokens from those wallets. About 500 wallets approved the malicious allowances. The Badger team halted further theft by pausing contract calls; deposits in the smart contracts themselves were unaffected. [1][2]
Bracketed numbers refer to the numbered sources listed below.
Sources (2)
See also
World Liberty Financial (WLFI) — Justin Sun token freezeProjectsWLFI, a DeFi project linked to Donald Trump and his family, blacklisted/froze the wallet of major investor Justin Sun in Sept 2025 — ~540–595M unlocked WLFI tokens (~$107M) plus ~2.4B locked. Sun sued, alleging an undisclosed admin 'blacklist backdoor'; WLFI denied it and threatened a countersuit. The dispute is ongoing.
Gala Games exploitTokensOn May 20, 2024 an attacker abused a privileged minter account on the GALA token contract to mint 5 billion GALA (≈$200M+ nominal) and dumped ~600M of them for ~$22M of ETH before Gala froze the address. Gala Games called it an internal access-control failure; the attacker later returned the ~$22M.
This page was last updated on Jun 15, 2026. View revision history.
