Worked example · 2024
Curio DAO MakerDAO fork-chain governance exploit — Ethereum — 2024-03
Summary
Curio DAO deployed a MakerDAO-derived stablecoin infrastructure including collateral-management, liquidation, and governance contracts. The codebase was forked from MakerDAO's MCD system — a complex governance-gated multi-collateral stablecoin architecture. MakerDAO secures its governance surface through a large, distributed token-holder base, multi-day governance delays, and an active security community that monitors governance proposals. Curio's fork inherited the technical governance surface but operated with a significantly smaller governance-token distribution and without the equivalent governance-process mitigations.
The attacker exploited the gap between the technical governance surface (identical to MakerDAO's) and the social-layer governance security (substantially weaker than MakerDAO's). The attack drained approximately $16M in collateral assets through a governance-parameter manipulation that the fork's governance process did not have the delay, quorum, or community-monitoring density to resist.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2024-03 | Attacker exploits governance-parameter manipulation vulnerability in Curio's MakerDAO-forked infrastructure; ~$16M drained | T9.007 + T9.003 + T16.002 |
Public references
- Curio DAO post-mortem and community communications (March 2024).
- MakerDAO MCD codebase and governance documentation — the upstream substrate Curio forked.
- On-chain transaction data on Etherscan.