Key Highlights:
- A missing access control vulnerability allowed an attacker to drain four separate 50 ETH batches left over from the historic Black Thursday event.
- Security firm CertiK verified the exploit origin, and the perpetrator laundered the extracted Ethereum in 10-ETH installments via Tornado Cash.
- Although the targeted keeper implementation contract was not an active core component of the modern Sky ecosystem, it retained dormant assets vulnerable to exploitation.
Security Exploit Targets Legacy Black Thursday Contract Assets
A dormant legacy contract tied to historical decentralized finance operations has been drained of assets following an access control vulnerability. Blockchain cybersecurity firm CertiK identified the technical flaw that allowed the malicious actor to siphon funds that had remained undisturbed for roughly half a decade.
According to CertiK’s analysis the root cause was a missing access control on function 0x8804d1de in keeper implementation 0x68399ed8aa33C5b43F863EE6782de492006A5546.
The absence of permission checks on the specified keeper implementation enabled unauthorized interaction, granting the attacker the ability to trigger the asset transfers directly.
Laundering Operation Routes Ether Through Tornado Cash
Through this specific access failure, the perpetrator successfully gained access to four lots of 50 $ETH that had remained sitting in the contract since the original Black Thursday market crash. After securing the 200 ETH balance, the attacker moved to obscure the audit trail, systematically routing the stolen cryptocurrency off-chain.
On-chain tracking confirmed that these illicitly extracted assets were laundered through privacy protocols. These funds were then sent in 10-$ETH lots through Tornado Cash, breaking down the balance into smaller, uniform transactions to minimize traceability.
Legacy Code and the Long Tail of Protocol Vulnerabilities
Security analysts noted that the exploited keeper contract wasn’t a core part of the current Sky ecosystem, however, this does serve as a reminder of the long tail of cryptocurrency risks. Even when decentralized networks evolve their protocol architectures, deploy upgraded versions, and rebrand their ecosystems, old infrastructure may remain active on the Ethereum blockchain.
Even contracts that haven’t been central for half a decade can still be lucrative targets for attackers if they contain real value. Unmaintained and abandoned deployments containing lingering balances can sit unnoticed by protocol guardians while remaining fully discoverable to specialized bad actors conducting comprehensive smart contract scans.
Why This Matters
The incident demonstrates the persistent challenge of technical debt within the decentralized finance sector. When decentralized protocols undergo major upgrades or pivot their branding—such as the evolution into the current Sky ecosystem—older automated helper contracts, liquidators, and keepers can fall outside regular security oversight while remaining permanently deployed on immutable networks. As long as legacy contracts house dormant tokens, they represent viable attack vectors capable of being drained years after their active lifecycle has concluded.
Frequently Asked Questions
What caused the security vulnerability in the keeper implementation?
The breach was caused by a critical absence of access control validations on function 0x8804d1de within the keeper implementation at address 0x68399ed8aa33C5b43F863EE6782de492006A5546, which allowed unauthorized execution by the attacker.
How much was taken, and how was it laundered?
The exploiter captured four lots of 50 ETH (a total of 200 ETH) that dated back to the Black Thursday crisis. The proceeds were then routed and laundered through Tornado Cash in individual 10-ETH installments.
Is the current Sky ecosystem core infrastructure affected?
No, the compromised contract was a non-core legacy deployment and not part of the active core operational architecture running the modern Sky ecosystem.




