Hedgey Finance hack — April 2024
Incident facts
| Date of incident | |
|---|---|
| Target type | Other |
| Loss | $44,700,000Published estimates range $2,000,000 to $45,000,000Price at time of incident |
| Method | Contract logic errorERC-20 allowance granted on campaign creation was never revoked on cancellation, and the lockup address parameter was unvalidated |
| Chains | Ethereum, Arbitrum, Fantom, Polygon, BNB Chain, Other |
| Outcome | Unresolved |
What happened
On 19 April 2024 an attacker drained token claim campaigns run through Hedgey Finance, a protocol projects use to distribute vesting and locked token allocations. Hedgey's own post-mortem times the exploit at 07:06:47 UTC and says that out of roughly 60 active claim campaigns, 23 lost funds.
The flaw was in the ClaimCampaigns contract. Creating a locked campaign approved the spend of the full deposited amount to what was meant to be a Hedgey vesting contract, but the lockup address parameter was supplied by the caller and never validated. Halborn identifies it specifically as the claimLockup parameter, the one input the function did not check. Cancelling the campaign returned the deposited tokens but never decreased the ERC-20 allowance, so the approval survived and could be spent with transferFrom. The attacker used a flash loan to fund a campaign, named an attacker-controlled contract as the lockup address, cancelled the campaign and then drained the tokens through the surviving approval. Hedgey's post-mortem describes this as a flashswap and does not name the lending venue; no cited source identifies which protocol supplied the loan.
Hedgey recorded roughly $45 million of notional value taken: about $40 million of it a single project's illiquid token on Arbitrum, 1.3 million USDC and 654 ETH on Ethereum, about $170,000 on Fantom, and small amounts on BNB Chain ($4,600), Polygon ($800) and Shimmer ($500). Contemporary reporting settled on $44.7 million, with Halborn splitting it $42.6 million on Arbitrum and $2.1 million on Ethereum and Cointelegraph $42.8 million and $1.9 million.
That headline is contested. CertiK's analysis argued the number came from multiplying stolen token quantities by quoted prices without regard to the liquidity backing them, and put the realised loss at about $2 million: roughly $1.3 million in USDC and about $600,000 in NOBL. Hedgey disabled creation of new claims, contacted affected projects to cancel campaigns, established whitehat bounties, tracked the exploiters with SEAL 911, commissioned four further audits and said it was coordinating with law enforcement on recovery.
Sources
- Hedgey FinancePrimary · retrieved 2026-08-01
- CertiKSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
- CointelegraphSecondary · retrieved 2026-08-01
Official post-mortem: https://medium.com/hedgey/hedgey-exploit-post-mortem-784e9860fd8d
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Hedgey Finance hack — April 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/hedgey-financehttps://itokenly.com/hacks/hedgey-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.