Hashflow Hack
What happened
On June 14, 2023, an attacker exploited a deprecated Hashflow contract across five EVM chains. Its callable transfer path lacked adequate access control, allowing anyone to use transferFrom to move tokens from wallets that had left approvals in place. About $640K in exposed user funds was affected.
Case & protocol details
Attack Timeline
A deprecated Hashflow contract retained a callable function that could invoke transferFrom against users' standing token approvals. Because its post-deprecation restriction logic was inadequate, an attacker could direct approved tokens from affected wallets to an attacker-controlled contract. The vulnerable function was not part of the audited codebase.
The attacker published a recovery contract and asked users to revoke the old approval before withdrawing, but stale allowances remained exposed to later theft. Hashflow said its active DEX was not affected.
Security review history
Funds Recovery
Recovered
$600K
Net Loss
$39,680
Post-Incident Timeline
-
2023-06-30
The protocol faced another exploit via an approval-related bug. $40,000 worth of $USDT and $USDC was stolen as a result of the exploit on the Arbitrum chain
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report twitter.com
- report Report twitter.com
- report Report twitter.com
- analysis CertiK: Post Mortem, Hashflow certik.com
- analysis SharkTeam: Analysis of the Hashflow Attack Incident sharkteam.org
- analysis Revoke.cash: Hashflow incident revoke.cash
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.