Hacken Token Hack
What happened
In June 2025, a compromised legacy bridge key with HAI minting authority was used to mint roughly 900 million unauthorized HAI across Ethereum and BNB Chain. The attacker sold tokens on BNB Chain; Hacken estimated the extractable loss at about $250,000, while the token's market value fell sharply from inflation and selling pressure. Hacken revoked the minter role, retired the old bridge design, and announced a snapshot-based migration for pre-incident holders.
How it happened
- A legacy bridge account held the HAI minter role.
- After human error exposed its private key, the attacker used valid authority to mint unauthorized supply across Ethereum and BNB Chain, then sold HAI through BNB Chain DEX liquidity.
- This was a privileged-credential compromise, not an authorization bug in the token contract.
- The project’s migration was holder remediation, not confirmation that the attacker’s extracted funds were recovered.
Protocol details
Evidence
- report @peckshieldalert incident report x.com
- report @TheBlock__ incident report x.com
- analysis Website reference fxleaders.com
- analysis Website reference crypto.news
- analysis DeFiLlama defillama.com
- analysis HAI infrastructure update hackenclub.medium.com
- analysis Hacken cites human error after private-key leak theblock.co
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.