Hegic Hack
What happened
The platform discovered a mistake in one of its smart contracts: ‘options.length' rather than ‘optionIDs.length.' This resulted in no liquidity for expiring contracts since user assets were locked whenever they did not utilize their options. Hegic spent $48K to fix the problem and reimburse impacted users.
Case & protocol details
Audit assessment
Review priorities based on the documented failure pattern in Hegic (April 2020).
Critical checks
- Verify every sensitive logic path is guarded by appropriate access controls and input validation
Review history
- PeckShield Report
A prior review is not a guarantee of safety, particularly when code changes after the reviewed version.
Funds Recovery
Recovered
$48K
Net Loss
$0
Evidence & learning
Sources and on-chain records
- report Report decrypt.co
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.