Badgerdao was attacked this time, and it looked like the front end was hijacked, and it happened to be operated by a large user, which led to authorization to other contracts.
In the future, you should really pay attention to whether the authorized address is the same as the contract address to be operated!