Hacken Token Hack

Reported loss $250K
Ethereum BNB Chain
Unauthorized minting with a legacy bridge key

What happened

In June 2025, a compromised legacy bridge key with HAI minting authority was used to mint roughly 900 million unauthorized HAI across Ethereum and BNB Chain. The attacker sold tokens on BNB Chain; Hacken estimated the extractable loss at about $250,000, while the token's market value fell sharply from inflation and selling pressure. Hacken revoked the minter role, retired the old bridge design, and announced a snapshot-based migration for pre-incident holders.

How it happened

  1. A legacy bridge account held the HAI minter role.
  2. After human error exposed its private key, the attacker used valid authority to mint unauthorized supply across Ethereum and BNB Chain, then sold HAI through BNB Chain DEX liquidity.
  3. This was a privileged-credential compromise, not an authorization bug in the token contract.
  4. The project’s migration was holder remediation, not confirmation that the attacker’s extracted funds were recovered.

Protocol details

Classification Compromised privileged minter key
Protocol Type Exploit/Access control
Implementation language Solidity
Protocol links Website @hackenclub

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.