Hedgey Finance Incident Analysis
ID: 1e18b892-f9b1-55d9-93dd-a29407d22340
STIX ID: report--1e18b892-f9b1-55d9-93dd-a29407d22340
Feed Name: CertiK Blog
### Executive Summary On 19 April 2024 Hedgey Finance was exploited due to a missing revoke-approval line in ClaimCampaigns.sol (0xBc452fdC8F851d7c5B72e1Fe74DFB63bb793D511), enabling attackers to grant themselves token approvals via createLockedCampaign(), cancel campaigns to withdraw funds, and then use transferFrom() to steal assets; the initial exploit stole ~1.3M USDC and overall realized losses are ~ $2M with additional stolen BONUS tokens that are largely illiquid. The report includes the vulnerable contract, attack flow, attacker addresses, stolen-fund movements, copycat activity, and a note on proper loss calculation and the importance of audits.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
