High Smart contract exploit Source: DeFiHackLabs

Add PoC: DAOstack permissionless newOrganization Reputation hijack

An attacker exploited a permissionless function in DAOstack's newOrganization to hijack an existing Reputation contract. The attacker drained the Genesis Alpha treasury, which held 4.025 ETH, by minting 20,000 REP and gaining full control.

Protocols
DAOstack
Chains
Ethereum
Confidence
High
First seen
27 Sep 2026, 03:31 UTC

On-chain references

Read the original report ↗ (opens in a new tab)