Polkadot attacker minted 1B $DOT and dumped for $237K; Dango protocol exploited for $410K the same day.
Security & Exploits ·
Polkadot and Dango both suffered security breaches within hours of each other. An attacker minted 1 billion $DOT tokens on Polkadot and converted them for $237,000, while Dango protocol was exploited for $410,010 in USDC.
The Dango exploit stemmed from a bug in the insurance fund's donation logic that failed to validate whether donated amounts were positive, allowing an attacker to drain USDC collateral from the perps contract. A bridge rate limit restricted the attacker's ability to move funds off the network; while $410,010 was successfully bridged to Ethereum, $1,490,012 remained locked in the attacker's account and inaccessible. The vulnerability was isolated to the insurance fund and did not affect order matching, PnL settlement, or liquidation systems.
Dango paused its chain and initiated recovery of the trapped funds while contacting security firm SEAL_911 and the stablecoin issuer Circle. The protocol stated all affected users would be compensated and the system would return to operation soon, though details on timeline and the Polkadot incident's root cause remain unclear. Dango invited the exploiter to negotiate a bug bounty and postponed its points program.