CryptoReal
CASE FILE — Mar 10, 2023

Hedera Halts Mainnet After $515K Theft Spirals Into $12M Ecosystem Fallout

An unclear, fast-moving threat shook the entire Hedera ecosystem the day before this report, sending both users and developers scrambling to understand what was happening.

Hedera describes itself as a "proof-of-stake public ledger" built on Hashgraph rather than a traditional blockchain. Its total value locked fell by a third during the attack, dropping from $36.8 million to $24.6 million. The HBAR Foundation announced "network irregularities," and given how broadly the disruption seemed to spread, users rushed to move funds to safety.

Multiple apps across the network were affected, including the AMMs Pangolin and Heliswap. SaucerSwap initially flagged concern before later confirming its users had not been impacted. The Hashport bridge was taken offline in response.

The uncertainty amplified the damage considerably: what turned out to be roughly $515,000 actually stolen by the attacker translated into an estimated $12 million in broader ecosystem losses once the panic and disruption were factored in. Hedera later said it would turn off network proxies on mainnet, making the network inaccessible to users; at the time of the original report the network remained down while investigations continued.

Sums referenced in this case file

Exactly how the exploit was carried out wasn't fully detailed, but Hedera confirmed the root issue sat in the network's Smart Contract Service code. In a Twitter thread, Hedera explained that the attacker had "targeted accounts used as liquidity pools on multiple DEXs that use Uniswap v2-derived contract code ported over to use the Hedera Token Service" — a service that had been audited by FP Complete back in 2021.

Pangolin's team lead published a preliminary writeup noting that responders initially believed the issue was limited to Hashport-bridged tokens — a theory that "proved to be false," since further investigation showed every HTS (Hedera Token Service) token was at risk. The flaw let the attacker burn wrapped or bridged tokens and pull liquidity positions from the affected DEXs. Per that report, some of the stolen funds were bridged back to Ethereum before Hashport shut the bridge down, after which the attacker moved to centralized exchanges instead.

The attacker's Hedera account has been identified. According to the writeup, Pangolin's losses came to $120,000, while Heliswap's own summary put its losses at just $2,000. Across the attacker's known addresses, roughly $515,000 in assets has been traced in total: about $60,000 in HBAR and $280,000 in HTS-based stablecoins on Hedera, plus $175,000 in ETH on Ethereum. Despite the incident, Hedera's native token HBAR held up better than much of the broader market, which was falling at the time regardless.

The episode arrived on the heels of the MyAlgo wallet-draining incident just a week earlier, meaning the discovery that this attack wasn't confined to a single protocol landed on an already jumpy market. Pausing the network may have protected some user funds, but taking a supposedly decentralized chain offline sits awkwardly next to Hedera's governance model, whose members — companies such as Boeing, Dell and Ubisoft — are not typically associated with DeFi-native values. Full clarity on the exploit's mechanics was expected to emerge over the following days, though for many users the damage, and the reputational cost of the shutdown, had already been done.

EcosystemHedera
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.