On October 6th, a new address funded by Tornado Cash extracted 200 WETH from a dormant MakerDAO ETH-A clearing robot agent, resulting in a loss of approximately $538000. The agent won 4 ETH-A clearing auctions in 2020, each receiving 50 WETH, but the collateral was retained due to the failure to call deal(). The extraction function for implementing the contract is not protected by ds auth, and the attacker transfers 200 WETH tokens out by calling deal(), Vat.flux, and GemJoin.exe. The MakerDAO core contract is running normally, but the vulnerability lies in the exit function of the third-party robot without permission control set.