logo

Hedgey Finance Incident Analysis

ID: 1e18b892-f9b1-55d9-93dd-a29407d22340

STIX ID: report--1e18b892-f9b1-55d9-93dd-a29407d22340

Feed Name: CertiK Blog

Threat Score
65/100

Date Published: 2024-05-06

Date Updated: 2026-06-11

...
...

### Executive Summary On 19 April 2024 Hedgey Finance was exploited due to a missing revoke-approval line in ClaimCampaigns.sol (0xBc452fdC8F851d7c5B72e1Fe74DFB63bb793D511), enabling attackers to grant themselves token approvals via createLockedCampaign(), cancel campaigns to withdraw funds, and then use transferFrom() to steal assets; the initial exploit stole ~1.3M USDC and overall realized losses are ~ $2M with additional stolen BONUS tokens that are largely illiquid. The report includes the vulnerable contract, attack flow, attacker addresses, stolen-fund movements, copycat activity, and a note on proper loss calculation and the importance of audits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.