HECO Hack
What happened
HECO's Ethereum bridge was drained on November 22, 2023 for approximately $86.6 million. The incident involved a compromised bridge operator account, not a permissionless bridge-contract flaw. Same-day HTX hot-wallet activity is a separate loss category and is not included in this page's amount.
Operator authority was the bridge custody boundary. Once the operator account was compromised, its privileged withdrawal calls were valid under the contract's access-control rules. Bridge operations need threshold key custody, isolated signer infrastructure, withdrawal caps and delays, plus monitoring and circuit breakers for anomalous releases.
Case & protocol details
How it happened
The attacker used the compromised operator account to call the bridge's operator-gated withdrawal functions on Ethereum. Because the onlyOperator check accepted the compromised credentials, the bridge released native ETH and ERC-20 assets to attacker-controlled addresses. The assets were then swapped and distributed.
The available evidence does not disclose how the operator credentials were compromised.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.