📈 Get daily crypto insights that make you smarter about your money

PeopleDAO Treasury Drained of $120,000 in Sophisticated Google Sheet Social Engineering Attack

On March 6, 2023, the PeopleDAO community disclosed a devastating breach of its treasury stored on the Safe (formerly Gnosis Safe) multisig platform, resulting in the loss of approximately $120,000 worth of Ethereum. The attack exploited not a smart contract vulnerability, but rather a fundamental breakdown in operational security — a compromised Google Sheet used to manage community reward distributions.

The Exploit Mechanics

The attack vector was elegantly simple yet devastatingly effective. PeopleDAO maintained a Google Sheet to track monthly contributor rewards, with the accounting lead publishing a link to a Google Form on a Discord channel that was inadvertently left accessible to the public. This form was used to collect Ethereum wallet addresses from community members who had earned rewards for their contributions.

The attacker exploited this publicly accessible form by injecting their own wallet address into the spreadsheet, disguised in a hidden format that made it virtually invisible during casual review. The malicious address was allocated 76 ETH — approximately $120,000 at the time — cleverly embedded within the legitimate list of reward recipients.

When it came time to distribute rewards, the signers exported the data from the CSV file on the Safe platform and approved the batch transaction. Six out of nine multisig signers failed to detect the hidden malicious address, and the transaction was executed, transferring 76 ETH directly to the attacker’s wallet.

Affected Systems

The breach affected multiple interconnected systems within the PeopleDAO infrastructure. The primary target was the Safe Platform multisig wallet, specifically the Genesis Safe Proxy contract at address 0xdd38609. The attacker’s receiving address was 0x6e5cc01, and the exploit transaction was recorded on-chain at 0x4bd2f69 on the Ethereum mainnet.

Beyond the immediate financial loss, the attack compromised the integrity of PeopleDAO’s entire reward distribution system, affecting trust between the community and its contributors. The PeopleDAO contract at 0xfb8ab4d and the related ConstitutionDAO contract were both implicated in the broader security review that followed.

Bitcoin was trading at approximately $22,430 at the time, while Ethereum hovered around $1,567, underscoring the significant value of the 76 ETH stolen from the treasury.

The Mitigation Strategy

In the aftermath of the breach, PeopleDAO implemented several critical security improvements. Access to all accounting documents and forms was immediately restricted to authorized personnel only, with public-facing collection endpoints disabled entirely. The organization transitioned to a zero-trust policy for all treasury-related operations.

The team reported the incident to both the FBI and FTC for formal investigation and potential fund recovery. On-chain analysis revealed that the stolen funds were deposited into two major exchanges — HitBTC and Binance — which may aid in the recovery process through cooperation with law enforcement.

Additionally, PeopleDAO recommended that Safe improve its user interface to display the gross transaction value prominently, including the total amount of ETH and PEOPLE tokens being transmitted, making it easier for signers to spot anomalies before approving transactions.

Lessons Learned

The PeopleDAO incident serves as a stark reminder that the weakest link in any decentralized organization’s security chain is often not the smart contract code itself, but the human-operated processes surrounding it. Multi-signature wallets are only as secure as the diligence of their signers. When six out of nine signers approve a transaction containing a hidden address, the fundamental assumption of distributed trust is called into question.

The attack highlights the critical importance of separating data collection from transaction execution. Using the same publicly accessible spreadsheet for both collecting wallet addresses and generating batch payment transactions creates an obvious attack surface that any motivated adversary can exploit.

User Action Required

For DAOs and decentralized organizations managing community treasuries, this incident demands immediate operational security review. Implement strict access controls on all data collection tools, ensure that multisig signers independently verify every transaction detail before signing, and consider using dedicated treasury management platforms that provide clear visual summaries of all outgoing transfers. Always adhere to the principle of least privilege and maintain a zero-trust posture for all financial operations.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before making any financial decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

27 thoughts on “PeopleDAO Treasury Drained of $120,000 in Sophisticated Google Sheet Social Engineering Attack”

  1. 76 ETH hidden in a cell with white text on white background. $120k gone because nobody hit ctrl+A before processing payouts. ops security in DAOs is a joke

    1. org_design_rat

      Faisal Q. the ctrl+A thing is real. I worked at a DAO where a contributor literally asked why their payout was 3x the approved amount. turns out someone hid rows with matching formatting. took 20 minutes to find

  2. a google sheet for managing $120K in rewards. you cannot make this up. the opsec gap in DAOs is terrifying

    1. ledger_pain_ a google sheet for a $120K treasury wouldnt pass a basic nonprofit audit. web3 governance has lower standards than a pta bake sale

    2. a google sheet for 120k in rewards. this is why DAOs need actual financial ops tools not free SaaS products

      1. Emeka N. nailed it, DAOs treating google sheets like a treasury management tool is wild. 120k gone because nobody pressed ctrl+A before a payout run

    3. a $120K treasury managed through a free google product. DAOs need to stop treating google workspace like enterprise financial infrastructure

    1. disguised formatting in a public google sheet. low tech but devastating. state actors use the same technique in corporate espionage

      1. sheet_ghost_ the hidden row trick is classic. seen it used in three other dao incidents. color text on white background, row height set to 0

        1. rekt_docs three incidents using the same hidden row technique and DAOs still use google sheets for treasury. insane lesson learned nothing

          1. row_hide_ three incidents with the same hidden row trick and zero industry-wide response. DAOs learned nothing from this

    1. public discord channel + public google form = basic opsec failure. the attacker probably spent 10 minutes planning this

      1. 10 minutes of planning and 10 minutes of execution. the return on effort for social engineering DAOs is absurd right now

  3. 76 ETH allocated through a multisig because nobody pressed ctrl+A on a google sheet. DAO treasury management in 2023 was the wild west

    1. Petra V. the attacker spent maybe 15 minutes filling out a public google form and walked away with 120k. lowest effort highest ROI attack in DAO history

  4. white text on white background in a hidden row. this technique has been used in at least three DAO exploits and nobody changed their workflow

  5. hidden rows in a public google sheet for 76 ETH and the multisig just signed it. hardware security means nothing when humans are the vulnerability

  6. a 120k treasury managed through a public google form with no access controls. this wasnt a hack it was negligence. the attacker just filled out a form

    1. sheet_blame_ the hidden row trick was clever though. embedding a wallet address in a spreadsheet cell formatted to blend in. low tech but effective because nobody audits google sheets line by line

  7. multisig_gaps_

    76 ETH allocated through a multisig that nobody cross-referenced against the original form submissions. the Safe itself worked fine, the humans approving transactions were the vulnerability

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$78,155.00+0.7%ETH$2,458.28+0.9%SOL$104.96+1.4%BNB$693.23+0.7%XRP$1.39+0.6%ADA$0.2008+0.4%DOGE$0.0847+0.2%DOT$0.8436+0.5%AVAX$7.33+1.0%LINK$11.40+0.7%UNI$4.89+11.8%ATOM$1.48-0.6%LTC$48.98-0.5%ARB$0.0865-0.8%NEAR$1.89+5.6%FIL$0.6816+0.3%SUI$0.7402+0.6%BTC$78,155.00+0.7%ETH$2,458.28+0.9%SOL$104.96+1.4%BNB$693.23+0.7%XRP$1.39+0.6%ADA$0.2008+0.4%DOGE$0.0847+0.2%DOT$0.8436+0.5%AVAX$7.33+1.0%LINK$11.40+0.7%UNI$4.89+11.8%ATOM$1.48-0.6%LTC$48.98-0.5%ARB$0.0865-0.8%NEAR$1.89+5.6%FIL$0.6816+0.3%SUI$0.7402+0.6%
Scroll to Top