Hope Finance Hack

TOTAL LOST $2.0M
Medium Access Control Attacks arbitrum

What happened

Hope Finance was rugpulled, with the scammer making off with approximately 1,860,000 $USD worth of $ETH

Hope Finance is DeFi protocol on the Arbitrum layer-2 chain. The protocol launched an algorithmic token $HOPE pegged to $ETH. The Hope ecosystem contains $HOPE, $DREAM, and $WISH tokens. The protocol was rugpulled by an EOA address that used a multisig wallet to modify the TradingHelper contract's router, so when SwapWETH sends the funds directly to the attacker's address instead of performing a normal swap. The attacker drained 1,095 $ETH which is worth approximately 1,860,000 $USD. All the stolen funds were transferred to the Ethereum chain through Celer and UniSwap and then to Tornado Cash using three addresses.

According to the project's official Twitter, the possible scammer was identified as Ugwoke Pascal Chukwuebuka, also the photo with the ID of the scammer was published in the same tweet.

Web3 Security company Cognitos had audited Hope Finance's smart contracts. Cognitos reported that audited smart contracts and deployed ones are not the same.

Attacker addresses:

https://arbiscan.io/address/0x4481a353…4a9113

https://arbiscan.io/address/0xdfcb9a03…3c6145

Malicious transaction:

https://arbiscan.io/tx/0xc9ee5ed2…6b77eb

Addresses used for TornadoCash transfer:

https://etherscan.io/address/0x957D354d…8fCecE

https://etherscan.io/address/0xB83dD80d…3120a5

https://etherscan.io/address/0x43B89dE7…7BA688

Case & protocol details

Classification Rugpull / Stablecoin / Access Control
Protocol Type Exit Scam/Rugpull
Affected asset / contract HOPE
Smart Contract Language Solidity
Official Website hopefinance.xyz/
Protocol Twitter/X @Hope_fin

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.