ChainBleedv0.1 · open intel
← back to feed·GOVERNANCE2022-02-15 · 4y ago
Incident · SLOWMIST

Build Finance

Governance Attack
Estimated loss
VERDICT —UNRATED
Verdict pending. Auto-ingested incidents are reviewed before a public verdict is rendered.
▰ METHOD
GOVERNANCE
GOVERNANCEBYTECODE CATCHABLEAI SCANNABLE
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

▰ PROOF OF CONCEPT
DEFIHACKLABS
src/test/2022-02/BuildF_exp.sol
view forked test on github ↗

Reproducible Foundry test fork from SunWeb3Sec/DeFiHackLabs. Clone the repo, run forge test against the file path above, and replay the exploit against a mainnet fork at the historical block. Use for reproduction only — not for live targets.

Forensic narrative

The venture capital DAO organization Build Finance tweeted that the project suffered a malicious governance takeover. The malicious actors successfully controlled the Build token contract by getting enough votes, minting 1,107,600 BUILD tokens in three transactions, and spent With most of the funds in Balancer and Uniswap liquidity pools exhausted, attackers continue to take control of the balancer pools via governance contracts and drain the remaining funds including 130,000 METRIC tokens, METRIC liquidity on Uniswap and Fantom Both pools subsequently came under intense selling pressure. As it stands, attackers have full control over governance contracts, minting keys, and treasuries, and the DAO no longer controls any part of critical infrastructure. Attack method (per SlowMist): Governance Attack. Reported loss: 168 ETH.

Primary source
https://twitter.com/finance_build/status/1493223190071554049
Sourced from
slowmist
Technical record
chain
protocol
Build Finance
bug_class
governance
date_occurred
2022-02-15
loss_usd
source_id
sm:build-finance::2022-02-15
Related — same bug class· governance
2025-12-30
5mo ago
STORY
Unleash Protocol
Multisig Governance Hack
governance
$3.90M
UNRATED
2024-02-25
2y ago
Tornado Cash
Governance Attack
governance
UNRATED
2023-10-19
2y ago
Synthetify
Governance Attack
governance
$230.0K
UNRATED
2023-07-02
2y ago
ETH
Aave fork
Governance Attack
governance
$930.0K
UNRATED
2023-06-11
3y ago
BSC
Atlantis Loans
Governance Attack
governance
$1.00M
UNRATED
2023-05-20
3y ago
Tornado Cash
Governance Attack
governance
$2.17M
UNRATED
ChainBleed — live web3 threat intelligence