Holograph hack — June 2024
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | June 13, 2024 |
| Target type | Token contract |
| Loss | $14,400,000Published estimates range $6,400,000 to $14,400,000Price at time of incident |
| Method | Insider actionA former technical contractor retained unauthorised administrative rights over Holograph Protocol v1 contracts and used a proxy wallet to mint one billion HLG through the protocol's v1 contracts, then sold the tokens on the open market and converted proceeds to stablecoins and ETH. |
| Chains | Ethereum |
| Attributed to | Unnamed former Holograph technical contractor; on-chain activity linked to the wallet acc01ade.eth. Four suspects were identified in an Italian-French police investigation, two of whom were arrested in Italy in August 2024.Alleged |
| Outcome | Arrests or charges |
What happened
On 13 June 2024 someone with administrative access to Holograph Protocol's v1 contracts minted one billion HLG tokens through a proxy wallet and sold them into the open market. HLG fell sharply the same day: The Defiant recorded a drop of about 54 per cent, from roughly $0.014 to $0.0064, and CoinDesk put the fall at over 60 per cent.
The headline figure is disputed because it depends on which price is applied to the newly minted tokens. Holograph's own account, Cointelegraph and the subsequent law-enforcement case describe about $14.4 million of HLG minted, valuing the tokens at the pre-exploit price; BleepingComputer's report on the arrests used $14 million. CoinDesk valued the same one billion tokens at slightly more than $6.7 million and The Defiant at about $6.4 million, using prices after the market had already fallen. The amount the attacker actually realised in ETH and stablecoins has not been established in the sources used here, so the range spans the post-crash and pre-exploit valuations of the same one billion tokens.
Holograph published a post-mortem on 2 July 2024 after an investigation with security firm Halborn, saying a disgruntled former contractor with unauthorised admin access had planned the exploit months in advance. On-chain analysis linked the wallet acc01ade.eth, whose operator had contributed code to the project, to the exploit; CMT Digital analyst Matt Casto suggested on the day that the culprit was a rogue developer who had funded the address 26 days earlier. Holograph patched the contract and worked with exchanges on the stolen funds.
In August 2024 Italy's Polizia di Stato, working with the French National Police, arrested two suspects in Salerno; two others were investigated but not arrested. Police seized wallet private keys and electronic devices. No conviction has been reported.
Law enforcement
France's National Police (including the cybercrime office and the Brigade de Répression du Banditisme) with Europol, Italy's Polizia di Stato and Directorate of Anti-Mafia Investigations, and the Royal Cayman Islands Police Service. Two suspects were arrested in Italy in August 2024 pending extradition to France; private keys and devices were seized.
Sources
- CoinDeskSecondary · retrieved 2026-08-01
- The DefiantSecondary · retrieved 2026-08-01
- CointelegraphSecondary · retrieved 2026-08-01
- BleepingComputerSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Holograph hack — June 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/holographhttps://itokenly.com/hacks/holographPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.