ChainBleedv0.1 · open intel
← back to feed·SOCIAL-ENGINEERING2023-03-06 · 3y ago
Incident · SLOWMIST

PeopleDAO

Permission Stolen
Estimated loss
VERDICT —OUT OF SCOPE
Root cause is social engineering — privileged personnel deceived into authorizing the drain. Contract behaved as written. Defense lives in process controls (multi-party approval, M-of-N signoff windows), not in smart-contract review.
▰ METHOD
SOCIAL ENGINEERING
SOCIAL-ENGINEERING
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

Forensic narrative

When PeopleDAO’s community treasury multi-signature wallet on the digital asset management platform Safe (formerly Gnosis Safe) distributed monthly contributor rewards on March 6, 76 ETH (approximately $120,000) were stolen by hackers through social engineering attacks. This event has nothing to do with the PEOPLE token contract. PeopleDAO collects monthly contributor reward information through Google Form. The person in charge of accounting mistakenly shared a link with editing permissions in the Discord public channel. Payments to your own address and set them to be invisible. Due to the malicious concealment, the team leader did not find it during the review. After downloading the csv file with insertef data, it was submitted to Safe's CSV Airdrop tool for reward distribution. With the assistance of SlowMist and ZachXBT, the team found that the attacked funds had been deposited in two exchanges, HitBTC and Binance, and contacted the two exchanges. Attack method (per SlowMist): Permission Stolen. Reported loss: 76 ETH.

Primary source
https://www.panewslab.com/zh/sqarticledetails/bv6m85qy.html
Sourced from
slowmist
Technical record
chain
protocol
PeopleDAO
bug_class
social-engineering
date_occurred
2023-03-06
loss_usd
source_id
sm:peopledao::2023-03-06
Related — same bug class· social-engineering
2026-05-11
1mo ago
SOL
Roaring Kitty X Account → $RKC memecoin pump-dump
X account takeover → coordinated memecoin pump-and-dump on Pump.fun
social-engineering
$2.86M
OUT OF SCOPE
2026-04-01
2mo ago
SOL
Drift Protocol
DPRK-linked Privileged-Access Drain
social-engineering
$286.00M
OUT OF SCOPE
2026-02-23
3mo ago
WLFI
Social Engineering
social-engineering
OUT OF SCOPE
2025-09-01
9mo ago
BSC
OlaXBT
Multisig wallet Social Engineering Exploit
social-engineering
$2.00M
OUT OF SCOPE
2025-07-24
10mo ago
MULTI
WOO X
Social Engineering
social-engineering
$14.00M
OUT OF SCOPE
2025-04-27
1y ago
QuantMaster
Insider Manipulation
social-engineering
$100.0K
OUT OF SCOPE
ChainBleed — live web3 threat intelligence