Holograph Hack
What happened
On June 13, 2024, a former Holograph contractor used retained administrative access to mint one billion unauthorized HLG tokens through the protocol's operator workflow. The tokens were bridged and sold, sharply diluting supply and crashing HLG's price.
Legacy administrator access remained powerful enough to authorize arbitrary operator work. The protocol lacked sufficient separation, revocation, and monitoring of privileged job creation and mint authority.
Case & protocol details
Attack Timeline
The former contractor had privileged access to Holograph Protocol v1 contracts and used a proxy wallet to insert a malicious operator job before the incident. Executing that job bypassed the intended verification process and minted one billion HLG. The tokens were moved from Mantle to Ethereum and sold through available venues.
The unauthorized mint was worth about $14.4 million at the incident-time valuation, but the selloff immediately reduced the token's price and liquidity. That figure is retained as the notional value of the minted supply, not represented as confirmed realized attacker proceeds.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report coindesk.com
- analysis Website reference x.com
- analysis Website reference x.com
- analysis Website reference blockchaingroup.io
- analysis Holograph Protocol Sabotaged by Former Contractor cointelegraph.com
- analysis HLG Supply-Removal Update news.bitcoin.com
- analysis HLG Falls After Unauthorized Mint coindesk.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.