Compromised Keys Drain $1.75M From Harmony-Based 8ight Finance
8ight Finance, an Olympus-model fork operating on the Harmony chain, saw its users lose a combined $1.75 million in an incident the team attributed to "compromised keys."

According to the project's own account of events, the funds moved out through four identifiable transactions: an initial withdrawal of 490,170 DAI, a second covering 378,417 DAI plus 10,843 LP tokens, a third moving 12,362 USDT, and a fourth transferring 868,587 DAI between two internal accounts (labelled "xxca1d" and "cc541" by the team) before the proceeds were funneled into Tornado Cash.
8ight had previously claimed to operate under multi-signature protection, but no such safeguard was actually in place — leaving the protocol exposed to a basic security failure rather than a sophisticated exploit. That gap, combined with reports that credentials had at some point been posted on Facebook and in a Google Doc, has fueled suspicion among some observers that the developer may have been involved in moving the funds personally rather than losing them to an external party.
Affected users have reportedly been discussing how to pursue the party responsible, though such efforts rarely succeed in cases like this. Whether the loss stemmed from an outside attacker or an inside job, questions remain about whether the team behind 8ight has a track record of similar incidents under different branding.
In the end, $1.75 million was lost, and the operational security failures involved — including the continued use of Facebook for sensitive material — arguably overshadowed the technical side of the story. Whatever the precise cause, the outcome for users was the same: funds gone, with the underlying nature of the incident, hack or rug, left unresolved.

Get new scam files the moment we publish them — usually 2–3 emails a week.