CryptoReal
CASE FILE — Jun 24, 2025

Hacken's Own Bridge Key Leak Wipes Out 99% of HAI's Value

Web3 security firm Hacken built its reputation auditing other people's protocols. On June 20th, its own infrastructure was the one that failed: a compromised bridge private key led to roughly $170,000 in stolen funds and a 99% crash in the price of its HAI token — the result not of a novel exploit, but of a basic key-management lapse during a bridge upgrade.

How it unfolded

PeckShield flagged the crash first on June 20th, reporting that "$HAI is hacked, resulting in price crash." Cyvers followed with more detail, confirming that the attacker had obtained minting privileges and used them to mint 900 million HAI tokens.

The root cause, per Hacken's own later account, was a bridge private key left exposed on a decommissioned DigitalOcean server — infrastructure that had apparently been forgotten rather than properly retired. Hacken shut down the bridges once the issue was identified, but by then tokens were already moving across both BSC and Ethereum.

Thin liquidity limited the actual damage: only about $170,000 was ultimately extracted, even though the token's market price fell 99%.

The response

CEO Dyma Budorin was active through the night, posting at roughly 3am that "We are online and making investigation" while the team was still assembling the full picture. He followed up shortly after: "This accident pushed us to an action. We will merge into Hacken security token with all legal rights."

He later confirmed the cause directly — a bridge private key compromise — calling it his "worst day," and said VeChain's solo-chain architecture would help contain further fallout.

By June 21st, Hacken's formal position was that this had not been a hack in the traditional sense but "human error during architectural changes." The company's post-incident report noted that the deployer wallet itself was never compromised — only the minter-role keys leaked — and stated that a bridge security upgrade had already been planned independent of the incident. Hacken put the total loss at approximately $170,000.

On-chain details

The attacker made no attempt to obscure the destination wallets:

Sums referenced in this case file

Minting transactions on BSC: 0xe8c895df8d99d3a680faf80bb65f80c53d8f2c48b5d48fe7c73883b6824aa30f, 0x4836db1d5a038a616d99ae396d73129272123733e394a43ee99d019b26eb142f, and 0xd082fcfe41d20a42f979acea0b03c50c35c5dd97e61d3df8386a9463b13d7f58.

Minting transaction on Ethereum: 0xa0b32ee67d572df80a10c439d395a9907492d6ef62cbf53be66b3145cf479ab6.

In total, 900 million tokens were minted across the two chains and quickly sold off — no smart-contract exploitation was needed once minting control was in the attacker's hands.

Market fallout and opportunistic trading

The chaos created an unintentional arbitrage opening: Gate.io's API allowed ETH-network deposits even though its user interface did not display that option. Traders who noticed the mismatch accumulated tokens on the affected chains and resold them on other venues before the gap closed.

After the 99% crash, HAI staged an 8x recovery bounce, and traders who bought the dip at the right moment profited, while the token continued trading at multiples of its crashed price across different exchanges simultaneously.

Tracking down the attacker

Three days after the incident, Budorin announced on Twitter/X: "Thanks to Extractor, we were able to track all fund movements and timely block the account after his KuCoin deposit." The attacker's mistake was depositing the proceeds on KuCoin, a KYC-compliant exchange, which gave investigators a real-world identity trail to follow. Hacken indicated that law enforcement was subsequently involved.

Hacken's proposed path forward

Alongside the investigation, Hacken outlined plans to convert HAI into a regulated financial instrument combining token utility with equity rights, to merge it with Hacken's equity holdings at a valuation of over $100 million, and to compensate affected holders through a future token swap.

The irony

Hacken's own Q1 2025 security report had identified access control failures as the top threat facing Web3, tying them to $1.6 billion in losses industry-wide, and stated that "while smart contract vulnerabilities remain a threat, most damage is now caused by failures in people, processes, or permission systems." Five years of postponed multisig upgrades ultimately caught up with the firm in the form of 900 million improperly minted tokens and a 99% price collapse — an outcome that closely matches the risk pattern its own research had flagged. Hacken has said it intends to turn the episode into a public case study for the industry.

Bridge Key CompromiseHacken
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.