CryptoReal
CASE FILE — Feb 22, 2023

Multisig-Approved Exit Scam Empties Hope Finance for $1.86M

Hope Finance, an Arbitrum-based fork of Tomb Finance, lost approximately $1.86 million on a Monday in what its own team publicly described as an inside job.

The project's official account posted a tweet blaming a specific team member for "rugging" the protocol, accompanying the accusation with that person's KYC information. Hope's comms also published blunt instructions telling users how to use the emergencyWithdraw function to try to pull out their staked LP tokens before further losses.

Despite the team's framing of a single rogue developer, the transaction that set up the rug pull had been approved by all three signers on the project's multisig wallet. It's also worth noting that fabricated KYC documentation is not difficult to obtain, leaving real doubt about whether the named individual was actually responsible.

How the funds were drained

Per an analysis published by Certik, the exit scam was staged in several steps. A fake router contract was deployed in one transaction. The project's SwapHelper contract was then updated to point to this fake router, in a transaction approved by all three owners of Hope's multisig (address 0x8ebd0574d37d77bdda1a40cdf3289c9770309aa7). A subsequent transaction set the _swapExactTokenForTokens variable to a specific wallet address, 0x957d354d853a1ff03dda608f3577d24ea18fcece.

From there, whenever GenesisRewardPool.openTrade() was called to borrow USDC, the pool would transfer WETH to the TradingHelper contract to be converted into USDC. Instead of performing that swap as intended, the USDC was routed directly to the 0x957d... address. Because the _uSDC parameter had deliberately been left blank, that same receiving address was passed into the Uniswap V2 swapExactTokensForTokens() call, which then sent 477 WETH to the same wallet.

Sums referenced in this case file

In total, roughly $800,000 in WETH and roughly $1 million in USDC were drained from the GenesisRewardPool contract (address 0x1fc2ac2651e1959d9ae86c6b2270aaf3d799e56c) at launch. The USDC portion was subsequently swapped into ETH, bringing the total to 1,095 ETH, which was then bridged to Ethereum via Celer and deposited into Tornado Cash.

Key addresses identified in the incident:

  • Rug-preparation address: 0xdfcb9a03fbe9f616ee6827cd1b753238d53c6145
  • Rug-pull receiving address (used on both Ethereum and Arbitrum): 0x957d354d853a1ff03dda608f3577d24ea18fcece
  • Hope Finance multisig: 0x8ebd0574d37d77bdda1a40cdf3289c9770309aa7

Audit history

Hope Finance had undergone two audits before launch. Cognitos passed the code despite flagging two issues it classified as "major" — though neither related to the mechanism ultimately used in the exploit. AuditRateTech also reviewed the project; its full audit report has since been removed from its site, though a KYC certificate connected to the review remains published there.

Unresolved questions

Whether the individual publicly named and doxxed by the Hope Finance team actually bears responsibility for the rug pull remains unconfirmed. A Twitter user pointed out that the address listed on that person's ID reportedly corresponds to a vacant lot according to Streetview imagery, raising further doubt. Other explanations remain possible, including that the KYC documents were purchased or that the named individual was set up by someone else with access to the project's official communications. Whether anyone responsible will ultimately face consequences remains an open question.

Hope FinanceRugpull
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.