Hector Network Hack

Reported loss $2.7M
Ethereum
Arbitrary eligible-wallet assignment and redemption withdrawal

What happened

On January 15–16, 2024, an unauthorized wallet drained approximately $2.7 million from Hector Network's Ethereum redemption treasury. The affected contract used a centralized moderator role to designate eligible claimants for the Fantom-to-Ethereum liquidation process. That role added an attacker-controlled wallet as eligible, allowing it to invoke the redemption withdrawal flow and transfer treasury assets.

The evidence establishes misuse of a privileged access-control path; it does not establish whether the actor was an external key compromiser or a rogue insider.

Technical root cause

A centralized moderator could designate arbitrary eligible claimants for the redemption flow, which then transferred treasury USDC without independent validation.

How it happened

The redemption contract trusted a moderator-controlled AddEligibleWallet() function to define who could claim treasury USDC. Once an attacker-controlled address was added with a claimable amount, it could call mintWithdraw, which activated transferRedemption and released funds. The root issue was a single centralized authority able to create arbitrary claims without sufficiently independent validation or governance controls.

Protocol details

Classification Privileged redemption-claim authorization abuse
Protocol Type DeFi Protocol
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.