HECO Hack

REPORTED LOSS $86.3M
High Compromised operator key and privileged withdrawal ethereum

What happened

HECO's Ethereum bridge was drained on November 22, 2023 for approximately $86.6 million. The incident involved a compromised bridge operator account, not a permissionless bridge-contract flaw. Same-day HTX hot-wallet activity is a separate loss category and is not included in this page's amount.

Technical Root Cause

Operator authority was the bridge custody boundary. Once the operator account was compromised, its privileged withdrawal calls were valid under the contract's access-control rules. Bridge operations need threshold key custody, isolated signer infrastructure, withdrawal caps and delays, plus monitoring and circuit breakers for anomalous releases.

Case & protocol details

Classification Bridge Custody / Compromised Operator Authority
Protocol Type Exploit/Access control
Protocol Twitter/X @HECO_Chain

How it happened

The attacker used the compromised operator account to call the bridge's operator-gated withdrawal functions on Ethereum. Because the onlyOperator check accepted the compromised credentials, the bridge released native ETH and ERC-20 assets to attacker-controlled addresses. The assets were then swapped and distributed.

The available evidence does not disclose how the operator credentials were compromised.

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.