Holograph Hack

TOTAL LOST $14.4M
High Access Control Attacks Mantle Ethereum

What happened

On June 13, 2024, a former Holograph contractor used retained administrative access to mint one billion unauthorized HLG tokens through the protocol's operator workflow. The tokens were bridged and sold, sharply diluting supply and crashing HLG's price.

Technical Root Cause

Legacy administrator access remained powerful enough to authorize arbitrary operator work. The protocol lacked sufficient separation, revocation, and monitoring of privileged job creation and mint authority.

Case & protocol details

Classification Authorization Management / Unauthorized Mint
Protocol Type Exploit/Other
Smart Contract Language Solidity
Official Website www.holograph.xyz/
Protocol Twitter/X @holographxyz

Attack Timeline

The former contractor had privileged access to Holograph Protocol v1 contracts and used a proxy wallet to insert a malicious operator job before the incident. Executing that job bypassed the intended verification process and minted one billion HLG. The tokens were moved from Mantle to Ethereum and sold through available venues.

The unauthorized mint was worth about $14.4 million at the incident-time valuation, but the selloff immediately reduced the token's price and liquidity. That figure is retained as the notional value of the minted supply, not represented as confirmed realized attacker proceeds.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.