BlockBeats news, October 6th, according to Defimon Alerts monitoring, a new address funded by Tornado Cash withdrew 200 WETH from a dormant MakerDAO ETH-A liquidation bot proxy on October 6th, resulting in a loss of approximately $538,000. This upgradeable proxy had won four ETH-A liquidation auctions in 2020 (numbers 1457 to 1460, each 50 WETH), but did not call deal(), leaving the collateral in the Flipper.
The withdrawal function of the implementation contract was not protected by ds-auth, allowing any caller to trigger it: first call deal() on the aforementioned old auctions, then transfer the collateral to the keeper via Vat.flux, and subsequently GemJoin.exit transfers the 200 WETH to the caller-specified address and unwraps it into ETH. The MakerDAO core contracts operated as designed; the vulnerability lies in the third-party bot's unprotected exit function.

