MakerDAO Loans Can Be Gamed to Hold Out Funds From Liquidation, Startup Finds
A loophole in MakerDAO’s collateralized debt market enables positions to be closed far more leniently than intended due to an oversight in the auction process.
Borrowers can close debt positions on lending platform MakerDAO under the 150% collateral minimum with this one simple trick.
A loophole in MakerDAO’s collateralized debt positions (CDPs) market, discovered by Israel-based startup B.Protocol, enables CDPs to be closed far more leniently than the system intends due to a small oversight in the auction market, according to a blog shared early with CoinDesk.
The lending protocol is meant to close positions automatically after collateral backing outstanding
If borrowers split CDPs into tiny positions around $100, B.Protocol analysis shows, the Keepers – who bid on liquidated assets from undercollateralized positions – won't liquidate positions because of the difficulties in calculating the profit margin, B.Protocol CEO Yaron Velner said in a phone interview.
A position – big or small – could theoretically be held under the collateral limit for some time and be closed without a liquidation penalty, he said. Exact values were not provided because of the odd nature of the problem; how long an extension lasts depends on Keepers who don’t seem interested in purchasing small underwater positions, Velner said.
“Extrapolating these results to a Vault of $1M suggests that it will cost around $5K in gas to split it into 7,800 Vaults. Or in other words, one could protect his Vault from future liquidations by sacrificing only 0.5% of his Vault size,” the blog states.
That’s compared to the typical 13% or more haircut liquidated CDP holders usually sustain when their debt-to-loan ratios fall below the minimum threshold.
Liquidation heuristics
The finding puts pressure on MakerDAO’s liquidation markets, which are already being overhauled by the community. Creating and destroying the platform’s native dai stablecoin is dependent on Maker self-executing liquidations when appropriate. Yet, as B.Protocol puts it, “It is not clear such a threshold exists.” Rather, Keepers rely on vague “heuristics.”
“The core reason for the fact that small Vaults were not liquidated is likely because the liquidators did not find it profitable to initiate the liquidation process,” the blog states.
Read more: MakerDAO’s DAI Stablecoin Breaks $1B Market Cap
One decentralized finance (DeFi) arbitrage firm CoinDesk spoke with under the condition of anonymity concurred with B.Protocol’s assessment, adding that other DeFi lending schemes such as Aave or Compound are far simpler. “With those protocols we don't have to price things and just need to consider whether there is enough liquidity,” the source said.
The ten-thousand-foot picture is far more flattering, however. Not only has MakerDAO's total value locked (TVL) shot north of $2 billion, but its ability to address architectural slights on the fly throughout 2020 does give some credence to DeFi's ever-growing dependency on governance tokens.
The finding is B.Protocol’s second in the last few weeks, the last being the use of a flash loan on Maker’s governance portal to close an election early. (B.Protocol offers lending market liquidation products).
The startup disclosed the vulnerability to the Maker smart contract team, which is preparing options for community review Monday, Velner said.
More For You
Protocol Research: GoPlus Security

What to know:
- As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
- GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
- Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.
More For You
The Protocol: Stripe’s Tempo Testnet Goes Live

Also: ZKSync Lite to Sunset, Blockstream App Update, Axelar’s AgentFlux
What to know:
This article is featured in the latest issue of The Protocol, our weekly newsletter exploring the tech behind crypto, one block at a time. Sign up here to get it in your inbox every Wednesday.











