Hashflow Hack

TOTAL LOST $640K
Low Other

Summarize with AI

Affected Chain 2023 Incident surface
Recovered $600K 93.8% returned
All-Time Rank #946 By amount stolen
Protocol Type DEX Aggregator Target category

Incident Overview

Hashflow, a DEX on Ethereum, was exploited leading to losses of approximately 600,000 $USD.

On June 14, 2023, Hashflow, a crypto trading platform, encountered an approve-related exploit. This exploit led to the loss of around 600,000 $USD worth of digital assets including $USDT, $USDC, and $DAI.

The attacker who carried out the exploit provided a recovery function contract, suggesting they may be a white hat hacker, preventing further losses. Users were instructed to revoke approvals before recovering funds. Two options were given for fund recovery, one for total funds and the second to donate 10% to the white hat hacker.

In the aftermath of the incident, Hashflow's native token, HFT, fell by 7% within 12 hours.

Attacker Address:

https://etherscan.io/address/0xBDf38B74…007E84

Malicious Contracts:

https://etherscan.io/address/0xddb19a1b…769216

https://arbiscan.io/address/0x04699818…ca249f

https://bscscan.com/address/0x91d08718…727065

https://polygonscan.com/address/0xbcb8eb2e…4b8072

https://snowtrace.io/address/0x91d08718…727065

Malicious Transaction Examples:

https://etherscan.io/tx/0xdedda493…2f4042

https://etherscan.io/tx/0x08b5f350…f05dce

Example of Recovery Transaction:

https://etherscan.io/tx/0xf6e6a0ee…6ed79a

Incident Report

Protocol / Project Hashflow
Date of Incident
Attack Technique Other
Classification Exchange (DEX)

Protocol Information

Protocol Type DEX Aggregator
Affected Token HFT
Official Website hashflow.com
Protocol Twitter/X @hashflow
Team Public / Doxxed
Source Code Verified On-Chain

Market Context at Time of Hack

Token Categories
Collectibles & NFTs Decentralized Exchange (DEX) Token DeFi Gaming Interoperability DAO Ethereum Ecosystem DEX

What the Attacker Needed to Succeed

Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.

Technical Knowledge Deep understanding of other and Solidity and EVM internals
Capital Required Seed capital to cover gas and initial position setup
On-Chain Access Ability to interact with smart contracts and deploy a custom exploit contract
Protocol Analysis Identification of the exploitable vulnerability in Hashflow's contract logic - root cause: exchange (dex)
Execution Speed Precise transaction ordering and timing to exploit the vulnerability within a single atomic block
Obfuscation Plan A strategy to launder and move stolen funds - typically through mixers, cross-chain bridges, or decentralized DEX swaps to resist tracing

What Auditors Should Check

Could this have been caught in audit? Likely — with a thorough Other audit checklist and test coverage

If you're auditing a protocol with similar architecture to Hashflow, these are the critical security checks that could have prevented this incident (June 2023).

  • Verify all logic paths related to Other are guarded by proper access controls and input validation
  • Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs

Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.

Free Trial

Funds Recovery

93.8%

Recovered

$600K

Net Loss

39680

Security Audit History

Bug Bounty Immunefi Details

Post-Incident Timeline

  • 2023-06-30

    The protocol faced another exploit via an approval-related bug. $40,000 worth of $USDT and $USDC was stolen as a result of the exploit on the Arbitrum chain

Sources & References

Learn to Prevent the Next Hashflow

The Hashflow hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.

Recreate exploit patterns safely Free Trial