BadgerDAO paused its smart contracts on December 2, 2021, after users reported unauthorized withdrawals from wallets interacting with the protocol. PeckShield, a blockchain security company tracking the transfers, estimated the affected assets at approximately $120.3 million in a December 2 snapshot, comprising roughly 2,100 bitcoin-equivalent tokens and 151 ether.
That figure was a contemporaneous security estimate, not an audited loss statement. The assets included wrapped and derivative positions whose dollar values changed with market prices, and early reports differed as investigators identified additional transfers. What was verified on December 2 was the movement of user assets, BadgerDAO’s acknowledgment of the incident and the protocol’s decision to halt contract activity while engineers investigated.
The interface, not the vault code
BadgerDAO was designed to bring bitcoin-linked liquidity into decentralized finance on Ethereum. Users deposited assets such as wrapped bitcoin into automated vaults and interacted with those positions through the project’s website. That architecture made the distinction between the web application and the on-chain contracts especially important.
Evidence available on December 2 pointed to the website’s front end rather than a flaw in the vault contracts themselves. Users had apparently signed token approvals that authorized an outside Ethereum address to transfer assets. Once those permissions existed, the attacker could call the tokens’ transfer functions without defeating the vault contracts’ internal accounting.
BadgerDAO’s initial public notice did not establish how the approvals had been solicited. Contemporaneous reporting cited project contributors who suspected that malicious code had been injected into the interface. The precise intrusion path remained under investigation, so claims involving a compromised Cloudflare credential were preliminary on December 2 and could not yet be treated as a completed forensic conclusion.
The distinction mattered beyond technical terminology. Smart-contract audits generally evaluate deployed blockchain code, but users also depend on domain controls, content-delivery systems, application code and wallet prompts. An attacker who changes the transaction presented by a trusted interface may obtain valid on-chain authorization even when the underlying protocol contracts operate as written.
Emergency controls limit further movement
BadgerDAO said it paused its smart contracts to prevent additional withdrawals. The pause demonstrated that the system retained emergency administrative controls despite its decentralized governance model. Those controls could restrict activity in Badger contracts, but they could not automatically reverse completed Ethereum transfers or cancel every token approval already granted to the attacker.
The response therefore raised two separate questions on December 2: how much had already left affected wallets, and how much remained exposed through outstanding approvals. Neither had a final answer within the event-day record. The $120.3 million PeckShield estimate should be read as a snapshot of identified transfers and then-current valuations, not a guaranteed recovery claim or a fixed accounting value.
For the broader DeFi market, the incident showed that protocol risk extended beyond exploitable contract logic. Wallet signatures, front-end deployment systems and infrastructure credentials could become part of the effective security boundary whenever a website assembled transactions for users.
Later-confirmed context
BadgerDAO’s subsequent technical post-mortem, prepared with cybersecurity firm Mandiant and released after December 2, attributed the incident to malicious code delivered through Cloudflare Workers using an unauthorized API key. The later account said the code intermittently prompted selected users to approve the attacker’s address and that Badger was alerted to suspicious activity at about 02:05 UTC on December 2.
Later Badger governance material counted 146 affected transactions from 145 wallets, excluding additional attempted transfers stopped or constrained by the pause. Those findings clarify the mechanism and scope but were not established facts available at the beginning of the December 2 response.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

