Hashflow Hack

TOTAL LOST $640K
Low Access Control Attacks arbitrum avalanche bsc ethereum polygon

What happened

On June 14, 2023, an attacker exploited a deprecated Hashflow contract across five EVM chains. Its callable transfer path lacked adequate access control, allowing anyone to use transferFrom to move tokens from wallets that had left approvals in place. About $640K in exposed user funds was affected.

Case & protocol details

Classification Exchange (DEX) / Access Control
Protocol Type DEX Aggregator
Affected asset / contract HFT
Smart Contract Language Solidity
Official Website hashflow.com
Protocol Twitter/X @hashflow

Attack Timeline

A deprecated Hashflow contract retained a callable function that could invoke transferFrom against users' standing token approvals. Because its post-deprecation restriction logic was inadequate, an attacker could direct approved tokens from affected wallets to an attacker-controlled contract. The vulnerable function was not part of the audited codebase.

The attacker published a recovery contract and asked users to revoke the old approval before withdrawing, but stale allowances remained exposed to later theft. Hashflow said its active DEX was not affected.

Security review history

Bug bounty Immunefi Details

Funds Recovery

93.8%

Recovered

$600K

Net Loss

$39,680

Post-Incident Timeline

  • 2023-06-30

    The protocol faced another exploit via an approval-related bug. $40,000 worth of $USDT and $USDC was stolen as a result of the exploit on the Arbitrum chain

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.