logo

HopeLend Incident Analysis

ID: c193fe04-74a6-58e9-9dc5-c3e99de06b2c

STIX ID: report--c193fe04-74a6-58e9-9dc5-c3e99de06b2c

Feed Name: CertiK Blog

Threat Score
75/100

Date Published: 2023-10-22

Date Updated: 2026-06-11

...
...

HopeLend was exploited when an integer-truncation bug in the hETHwBTC pool's discount calculation (liquidityIndex / rayDiv) allowed an attacker to manipulate the pool index via flash loans and empty-pool operations, inflating the value of a minimal hETHwBTC unit to borrow and drain multiple other pools; a front-runner captured part of the proceeds (527 ETH) and miner bribes were used, funds were later partly moved to a GnosisSafe and a 26 ETH bounty was negotiated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.