Hashflow Hack
Incident Overview
Hashflow, a DEX on Ethereum, was exploited leading to losses of approximately 600,000 $USD.
On June 14, 2023, Hashflow, a crypto trading platform, encountered an approve-related exploit. This exploit led to the loss of around 600,000 $USD worth of digital assets including $USDT, $USDC, and $DAI.
The attacker who carried out the exploit provided a recovery function contract, suggesting they may be a white hat hacker, preventing further losses. Users were instructed to revoke approvals before recovering funds. Two options were given for fund recovery, one for total funds and the second to donate 10% to the white hat hacker.
In the aftermath of the incident, Hashflow's native token, HFT, fell by 7% within 12 hours.
Attacker Address:
https://etherscan.io/address/0xBDf38B74…007E84
Malicious Contracts:
https://etherscan.io/address/0xddb19a1b…769216
https://arbiscan.io/address/0x04699818…ca249f
https://bscscan.com/address/0x91d08718…727065
https://polygonscan.com/address/0xbcb8eb2e…4b8072
https://snowtrace.io/address/0x91d08718…727065
Malicious Transaction Examples:
https://etherscan.io/tx/0xdedda493…2f4042
https://etherscan.io/tx/0x08b5f350…f05dce
Example of Recovery Transaction:
https://etherscan.io/tx/0xf6e6a0ee…6ed79a
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Hashflow, these are the critical security checks that could have prevented this incident (June 2023).
- Verify all logic paths related to Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialFunds Recovery
Recovered
$600K
Net Loss
39680
Security Audit History
Post-Incident Timeline
-
2023-06-30
The protocol faced another exploit via an approval-related bug. $40,000 worth of $USDT and $USDC was stolen as a result of the exploit on the Arbitrum chain
Sources & References
Learn to Prevent the Next Hashflow
The Hashflow hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.