Hector Network Hack
What happened
On January 15–16, 2024, an unauthorized wallet drained approximately $2.7 million from Hector Network's Ethereum redemption treasury. The affected contract used a centralized moderator role to designate eligible claimants for the Fantom-to-Ethereum liquidation process. That role added an attacker-controlled wallet as eligible, allowing it to invoke the redemption withdrawal flow and transfer treasury assets.
The evidence establishes misuse of a privileged access-control path; it does not establish whether the actor was an external key compromiser or a rogue insider.
A centralized moderator could designate arbitrary eligible claimants for the redemption flow, which then transferred treasury USDC without independent validation.
How it happened
The redemption contract trusted a moderator-controlled AddEligibleWallet() function to define who could claim treasury USDC. Once an attacker-controlled address was added with a claimable amount, it could call mintWithdraw, which activated transferRedemption and released funds. The root issue was a single centralized authority able to create arbitrary claims without sufficiently independent validation or governance controls.
Protocol details
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.