{"id":76624,"date":"2024-04-19T11:17:31","date_gmt":"2024-04-19T15:17:31","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=76624"},"modified":"2024-04-19T11:17:34","modified_gmt":"2024-04-19T15:17:34","slug":"hedgey-finance-loses-44-million-to-exploit","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/hedgey-finance-loses-44-million-to-exploit\/","title":{"rendered":"Hedgey Finance Loses $44 Million to Exploit"},"content":{"rendered":"\n<p>\u00a0Token infrastructure platform Hedgey Finance has experienced two concurrent <a href=\"https:\/\/coinscreed.com\/staging\/over-5-million-exploited-in-recent-defi-hacks-on-aave-and-yearn-finance.html\" target=\"_blank\" rel=\"noreferrer noopener\">Defi exploit<\/a>, resulting in the loss of funds totaling $44.7 million.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"886\" height=\"481\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-119.png\" alt=\"Hedgey Finance Loses $44 Million to Exploit\" class=\"wp-image-76633\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-119.png 886w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-119-300x163.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-119-768x417.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-119-750x407.png 750w\" sizes=\"(max-width: 886px) 100vw, 886px\" \/><figcaption class=\"wp-element-caption\">Hedgey Finance Loses $44 Million to Exploit<\/figcaption><\/figure>\n\n\n\n<p>A breach on the Arbitrum network affecting Hedgey compromised more than $42.8 million worth of Arbitrum (ARB) tokens, according to an April 19 X post by on-chain security firm Cyvers. An adversary has reportedly transferred a fraction of the stolen funds to the <a href=\"https:\/\/coinscreed.com\/staging\/bybit-simplifies-crypto-purchase-with-google-pay-integration.html\" target=\"_blank\" rel=\"noreferrer noopener\">Bybit cryptocurrency exchange<\/a>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-jnews-featured-750\"><img decoding=\"async\" width=\"750\" height=\"345\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-116-750x345.png\" alt=\"Smart contract vulnerability. Source: Cyvers\" class=\"wp-image-76630\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-116-750x345.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-116-300x138.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-116-768x354.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-116.png 949w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><figcaption class=\"wp-element-caption\"><em>Smart contract vulnerability. Source:\u00a0Cyvers<\/em><\/figcaption><\/figure>\n\n\n\n<p>A previous compromise of the Hedgey protocol on the Ethereum network compromised $1.9 million worth of cryptocurrency, as reported by Cyvers in an X alert.<\/p>\n\n\n\n<figure class=\"wp-block-image size-jnews-featured-750\"><img decoding=\"async\" width=\"750\" height=\"536\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-117-750x536.png\" alt=\"Hedgey exploit alert. Source: Cyvers\" class=\"wp-image-76631\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-117-750x536.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-117-300x214.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-117-768x549.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-117-120x86.png 120w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-117-350x250.png 350w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-117.png 907w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><figcaption class=\"wp-element-caption\"><em>Hedgey exploit alert. Source:\u00a0<\/em><a href=\"https:\/\/twitter.com\/CyversAlerts\/status\/1781271050073841735\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><em>Cyvers<\/em><span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a><\/figcaption><\/figure>\n\n\n\n<p>The Hedgey protocol has verified the exploit and stated that it is collaborating closely with auditors to identify the flaw that may be the source of the ongoing attack. An April 19 X post stated:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>\u201cWe're investigating an attack on the Hedgey Token Claim Contract. If you have created active claims, please cancel them using the \u201cEnd Token Claim&#8221; button\u2026\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p>Following Hedgey's confirmation of the exploit, fraudulent accounts posing as the protocol began to publish potentially harmful links beneath the thread. These links directed individuals to revoke their smart contract approvals or request a refund but had no affiliation with the Hedgey protocol.<\/p>\n\n\n\n<p>The breach transpired several hours before the highly anticipated Bitcoin halving, which aimed to halve the rewards for block issuance.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-over-500m-lost-to-hacks-in-q1-2024\">Over $500M Lost to Hacks in Q1 2024<\/h2>\n\n\n\n<p>Two hundred twenty-three breaches and exploits totaling more than $502 million in stolen digital assets occurred during the first quarter of 2024, according to the Hack3d report by on-chain security firm CertiK.<\/p>\n\n\n\n<p>This signifies a 54% surge compared to the initial quarter of 2023, during which funds valued at $326 million were stolen. January was the most profitable month for hackers, with 78 on-chain incidents resulting in the theft of over $193 million of cryptocurrencies.<\/p>\n\n\n\n<figure class=\"wp-block-image size-jnews-featured-750\"><img loading=\"lazy\" decoding=\"async\" width=\"750\" height=\"509\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-118-750x509.png\" alt=\"Hacks by type. \" class=\"wp-image-76632\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-118-750x509.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-118-300x203.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-118-768x521.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-118.png 932w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><figcaption class=\"wp-element-caption\"><em>Hacks by type. Source:\u00a0<\/em><a href=\"https:\/\/www.certik.com\/resources\/blog\/hack3d-the-web3-security-quarterly-report-q1-2024\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><em>CertiK<\/em><span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/figcaption><\/figure>\n\n\n\n<p>As in prior quarters, compromised private keys continued to be the leading vector of attack, resulting in the loss of more than $239 million across 26 incidents. CertiK reports that compromised private critical exploits constitute 11.7% of security incidents.<\/p>\n\n\n\n<p>Most of the returned funds, which amounted to more than $77.9 million, were traceable to the Munchables security breach.<\/p>\n\n\n\n<p>Immunefi identified the <a href=\"https:\/\/coinscreed.com\/staging\/north-korean-lazarus-group-holds-almost-50m-worth-of-crypto.html\" target=\"_blank\" rel=\"noreferrer noopener\">North Korean Lazarus Group<\/a> as the responsible party for 17% of the $1.8 billion in losses incurred in 2023 due to crypto breaches and scammers (December 28 report).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u00a0Token infrastructure platform Hedgey Finance has experienced two concurrent Defi exploit, resulting in the loss of funds totaling $44.7 million. A breach on the Arbitrum network affecting Hedgey compromised more than $42.8 million worth of Arbitrum (ARB) tokens, according to an April 19 X post by on-chain security firm Cyvers. An adversary has reportedly transferred [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":76633,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[7183,13889,19206],"class_list":["post-76624","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-defi-hacks","tag-arb-token","tag-hedgey-finance"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-119.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/76624","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=76624"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/76624\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/76633"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=76624"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=76624"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=76624"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}