Eden Network Hack
What happened
On December 8, 2025, Eden Network lost approximately 12 ETH and 1.24 million EDEN tokens (worth ~$54,000) through a vulnerability in the lockTokens() function that allowed the attacker to call transferFrom on any user account with token approvals and set an arbitrary startTime value, enabling immediate withdrawal of locked tokens by setting startTime to 1 and creating a lock with only 1-day duration and cliff periods.
The vulnerability resided in the token locker contract (0x64b51725…2c67e2) which failed to validate user inputs for the lockTokens() function, allowing the attacker to specify any address as the locker account and set arbitrary startTime values. By setting startTime to 1 (essentially Unix epoch +1 second), durationInDays to 1, and cliffInDays to 1, the attacker created a lock that was immediately claimable. The attack sequence shows the attacker transferring 3,350,859,533,447,232,218,765 EDEN tokens from an unsuspecting victim's address, creating a lock, immediately claiming the unlocked tokens, and then burning the LP tokens to extract 1,252,698,563,622,477,061,733,840 EDEN tokens and 12,143,448,341,679,353,263 wei of WETH from the SushiSwap EDEN-2 liquidity pool.
Protocol details
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.