CryptoReal
CASE FILE — Apr 19, 2024

Flash Loan Trick Drains $44.7M From Hedgey's Vesting Contracts

Hedgey Finance, a platform marketed as a leading provider of token vesting and lockup infrastructure, lost roughly $44.7 million across Ethereum and Arbitrum in a single flash loan exploit.

Cyvers was the first to flag suspicious activity, posting an alert on X. Hedgey's own team confirmed the attack a little over two hours afterward. In its statement, Hedgey told users who had open token claims to cancel them immediately through the "End Token Claim" button on its app in order to limit further damage.

The losses split unevenly between the two chains. On Ethereum, the attacker made off with about $2.1 million, pulled from a mix of USDC, NOBL, and MASA tokens. The far larger haul came from Arbitrum, where roughly $42.6 million in BONUS tokens was stolen.

Reactions from affected token communities varied. NobleBlocks (NOBL) published a detailed security writeup for its holders. Bonus Block's team briefly reassured its community that "our vestings are safe," while MASA's team focused its public attention on hosting a Twitter Spaces session rather than directly addressing the incident.

Mechanism of the exploit

Investigators traced the root cause to missing input validation in the vulnerable contract, which let the attacker manipulate parameters and extract token approvals they should never have been granted.

Sums referenced in this case file

The attacker first took out a $1.3 million USDC flash loan from Balancer. That capital was used to abuse the claimLockup parameter inside the createLockedCampaign function of Hedgey's contract, tricking it into approving a USDC transfer to the attacker's own contract. A second, separate transaction then executed the actual transfer of that USDC to the attacker — likely split into two steps specifically to avoid being intercepted by front-running bots.

A review of the contract's commit history confirmed the underlying flaw: user-supplied parameters were not adequately verified, which is what allowed token approvals to be granted to the attacker's contract in the first place.

Addresses involved

  • Exploiter address on Ethereum: 0xded2b1a426e1b7d415a40bcad44e98f47181dda2
  • Attack contract on Ethereum: 0xc793113f1548b97e37c409f39244ee44241bf2b3
  • Exploited contract on Ethereum: 0xbc452fdc8f851d7c5b72e1fe74dfb63bb793d511
  • Exploiter address on Arbitrum: 0xc7241e27ee4b8d32b59a10e848b48530047a8c5b
  • Attack contract on Arbitrum: 0xbb52f1723ddf2c84ba2668f4e04712f572cbf780
  • Exploited contract on Arbitrum: 0xbc452fdc8f851d7c5b72e1fe74dfb63bb793d511

As of reporting, the stolen funds remained sitting in the attacker's wallet, visible via DeBank.

Hedgey subsequently sent an onchain message to the attacker, framing them as a possible white hat and asking to discuss next steps — going as far as telling them "well done" for finding the bug.

Notably, Consensys Diligence had audited Hedgey's Token Lockup and Vesting Plans in June and July of 2023, prior to the incident.

Regardless of whether the actor turns out to be a white hat returning funds or a black hat cashing out, roughly $44.7 million left the protocol. Hedgey now faces the task of rebuilding user trust, which will likely require a broader security overhaul — stronger input validation, tighter access controls, and more rigorous auditing going forward.

Hedgey Finance
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.