DAO Maker disclosed on August 12, 2021 that an attacker had used a wallet with administrative privileges to remove roughly $7 million in USDC from accounts funding its token-sale platform. The company placed the incident at approximately 1:00 UTC and said 5,251 users were affected.
The breach was distinct from both MakerDAO, the protocol associated with DAI, and the Poly Network exploit dominating cryptocurrency headlines that week. It mattered because it exposed a different security boundary: users could interact through smart contracts, yet a privileged wallet still had authority over pooled balances.
A privileged path into user funds
DAO Maker said the attacker first withdrew 10,000 USDC as a test, then completed 15 additional withdrawals before its security team stopped the drain. The company characterized the event as malicious use of a wallet with administrator access. That wording established that privileged credentials or authority were involved; it did not establish on August 12 how the attacker obtained them.
BlockSec’s same-day transaction analysis mapped the control sequence. A deployer address had created the affected wallet contract. That deployer granted an administrator role to a second address, which in turn granted a “DAO contracts” role to an attacker-controlled contract. The attacker contract then called `withdrawFromUser` to transfer funds from the wallet.
This is a verified transaction path, not proof of identity or motive. The public ledger shows which addresses exercised permissions and which contract method moved balances. It cannot, by itself, distinguish a stolen private key, compromised internal system or insider action. Any stronger root-cause claim remained unproven at the event-day cutoff.
Measuring the loss
PeckShield told CoinDesk that 7,376,245 USDC moved from an address associated with the attacker to Uniswap and was exchanged for approximately 2,261 ETH. Because USDC was designed to track the U.S. dollar, contemporaneous reports described the loss as more than $7 million. That figure measures the token quantity transferred, not audited damages, later recoveries or the dollar value of the ETH at another time.
DAO Maker separately reported 5,251 affected users and an average loss of about $1,250. Those are rounded company figures and do not reconcile exactly with dividing 7,376,245 USDC by 5,251 accounts. The records may use different scopes or cutoffs, and DAO Maker did not publish enough account-level data on August 12 to resolve the difference. They should therefore be read as separate measurements, not as inputs to a precise calculation.
Containment did not equal recovery
DAO Maker said it moved unaffected funds to new wallets, kept withdrawals available for those funds and halted deposits while it conducted a root-cause analysis. It also said accounts with deposits below $900 were unaffected and that it had engaged blockchain-forensics firm CipherBlade. These were contemporaneous company claims, not independent attestations.
The company promised to contact affected users and develop a compensation plan over the following five days. On August 12, no completed reimbursement program, recovered-funds total or final forensic finding was yet available. The durable conclusion was narrower: an administrative control path had enabled a multi-million-USDC withdrawal from a platform that asked users to pre-fund token-sale participation.
Later context
A separate DAO Maker vesting-contract exploit occurred on September 4, 2021. That later incident involved different contracts and a different authorization flaw; it should not be folded into the August 12 loss or treated as information available on August 12.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

