Malicious Cloudflare worker injected approval prompts.
Attacker wallets funded and staged ahead of the frontend hijack exploit against BadgerDAO.
$120.0M drained from BadgerDAO on Ethereum via Frontend Hijack.
PeckShield flagged the anomalous transactions and published an initial alert.
BadgerDAO paused affected contracts or withdrawals and began tracing outbound flows.
Stolen assets followed through mixers, bridges, and exchange deposit addresses.
$9.0M of $120.0M recovered (8%); the remainder is still unaccounted for.
Remaining funds monitored across chains with exchange partners notified.