TempleDAO Loses $2 Million in Latest Exploit

Funds were converted to ether and moved to a new wallet

article-image

Source: DALL·E

share

key takeaways

  • An estimated 1.1 million TEMPLE was sold off
  • The root cause of the exploit was insufficient access control to the migrateStake function, according to BlockSec

TempleDAO, a yield-farming DeFi protocol, has been exploited for around $2.34 million.

All funds exploited were converted to ether and then moved to a new wallet, where they now sit. 

The pseudonymous Doc Peppercorn, a contributor to TempleDAO, posted on its Discord group that a series of transactions through Stax Finance, a TempleDAO-affiliated dapp, led to the sell-off of an estimated 1.1 million TEMPLE, the primary token of the Temple Protocol.

“We are investigating what happened so we can bring you the full picture of how this occurred, what we did to resolve and any further remediation steps,” he wrote.

The root cause of the exploit was insufficient access control to a specific function in the Stax smart contract, according to security firm BlockSec.

Prior to the exploit, TempleDAO’s protocol’s total value locked was about $57 million, according to DeFiLlama. The exploit amounted to roughly 4% of the protocol’s assets. 

According to a recent report published by bug bounty and security services platform, Immunefi, DeFi protocols remain a key target for exploits in comparison to centralized finance — representing a total of 98.8% of losses in Q3 of 2022 — with the Nomad Bridge hack and the Wintermute exploit making up the majority of the losses.

The two most targeted chains were Binance’s BNB Chain, which was recently drained of over 2 million BNB, and Ethereum, according to the report.

At the time when the report was published, the BNB Chain had suffered from 16 individual attacks resulting in the loss of 28.6% of all losses across targeted chains, and Ethereum reported 13 incidents which represented 23.2% of total losses.

The exploiter’s address was originally funded from an address on the Binance Exchange, so it’s possible the exchange may have know-your-customer information on the culprit.

A Binance spokesperson did not immediately respond to a request for comment.

Stax Finance is exploring its options.

Loading Tweet..

Temple DAO said that its Core Vaults do not share code with Stax and are therefore unaffected.


Get the news in your inbox. Explore Blockworks newsletters:

Tags

Upcoming Events

Old Billingsgate

Mon - Wed, October 13 - 15, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

Industry City | Brooklyn, NY

TUES - THURS, JUNE 24 - 26, 2025

Permissionless IV serves as the definitive gathering for crypto’s technical founders, developers, and builders to come together and create the future.If you’re ready to shape the future of crypto, Permissionless IV is where it happens.

Brooklyn, NY

SUN - MON, JUN. 22 - 23, 2025

Blockworks and Cracked Labs are teaming up for the third installment of the Permissionless Hackathon, happening June 22–23, 2025 in Brooklyn, NY. This is a 36-hour IRL builder sprint where developers, designers, and creatives ship real projects solving real problems across […]

recent research

Research Report Templates.png

Research

Ethena Labs is leaping from its flagship synthetic dollar, USDe, to a full product suite—USDtb, iUSDe, and the Arbitrum-based Converge Chain—designed to marry crypto-native yields with TradFi-grade compliance. Our analysis shows how expanding into CME, ETF options, and tokenized Treasuries could lift protocol revenue from sub-$500 million in a bear case to several billion dollars if favorable regulation and institutional adoption align.

article-image

The L1’s Interwoven Stack is the most opinionated tech stack yet

article-image

Bitcoin is still rising, 11 years after the documentary film The Rise and Rise of Bitcoin

article-image

Arch Labs CEO told Blockworks that the team plans to launch a native token, but declined to give details

article-image

CEO Mike Silagadze tells Blockworks that the US is “open for business” and why its DeFi bank offering is the first of many

article-image

Doing one thing well and leaving everything else out is often what disruptive technologies do best