{"investigation":{"slug":"hacken-token","entity_name":"Hacken Token","trust_score":42,"severity_base":null,"score_modifier":0,"confidence":0.78,"status":"published","content_type":"investigation","summary":"Hacken Token (HAI) is the native utility token of Hacken, a Ukrainian-founded Web3 cybersecurity company established in 2017 that audits smart contracts and blockchain infrastructure for over 1,500 clients worldwide. In June 2025, a private key controlling HAI minting privileges was compromised during a bridge infrastructure migration, allowing an attacker to mint approximately 900 million tokens and dump roughly $253,000 worth on decentralized exchanges, causing a near-99% price collapse. The incident drew industry-wide attention due to its irony — a company whose business model is built on securing others' blockchain infrastructure had maintained a single-key minting architecture for over five years without multisig protection.","sections":[{"content":"Hacken was founded in 2017 by Ukrainian cybersecurity researchers Dmytro (Dyma) Budorin and Yevheniia Broshevan, originally incorporated as Hacken OÜ in Tallinn, Estonia, with additional offices in Kyiv, Lisbon, New York, and Abu Dhabi. The company provides smart contract audits, penetration testing, proof-of-reserves verification, and compliance advisory services across more than 1,500 blockchain projects, including Bybit, MetaMask, the Ethereum Foundation, OKX, and Sui. HAI (Hacken AI Token) serves as the ecosystem utility token, used for staking, governance through the hDAO, access to premium cybersecurity services, and bug bounty rewards. HAI originally operated on both Ethereum (ERC-20) and Binance Smart Chain (BEP-20), connected via a custom cross-chain bridge. The token reached an all-time high of approximately $0.4659 and, prior to the June 2025 incident, had a market capitalization of roughly $12.7 million.","heading":"Background: Hacken and the HAI Token","sources":[{"url":"https://hacken.io/about/","name":"hacken.io","type":"other","credibility":3},{"url":"https://crypto.news/hacken-bridge-exploited-for-250k-hai-token-following-private-key-leak/","name":"crypto.news","type":"other","credibility":3},{"url":"https://www.coingecko.com/en/coins/hacken","name":"coingecko.com","type":"other","credibility":3},{"url":"https://coinmarketcap.com/currencies/hackenai/","name":"coinmarketcap.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On or around June 20–21, 2025, an attacker obtained a private key associated with an account holding minting privileges on Hacken's bridge contracts for both Ethereum and Binance Smart Chain. Using this key, the attacker minted approximately 900 million HAI tokens — nearly double the existing circulating supply — and subsequently dumped the tokens on BSC decentralized exchanges. The attacker realized approximately $253,000 in proceeds before liquidity constraints halted further sales. The HAI token price collapsed by approximately 98–99%, falling from around $0.015 to $0.000056. Hacken's market capitalization fell from roughly $12.7 million to $7.2 million. Hacken attributed the breach to 'human error' during architectural changes to the blockchain bridge infrastructure. The company confirmed the compromised key was tied to a legacy bridge deployment and revoked minter access upon discovery. Cross-chain bridge functionality between Ethereum and BNB Chain was subsequently paused indefinitely. The Etherscan token contract for HAI is 0x05Fb86775Fd5c16290f1E838F5caaa7342bD9a63 and the BscScan BEP-20 contract is 0xaa9e582e5751d703f85912903bacaddfed26484c.","heading":"The June 2025 Private Key Exploit","sources":[{"url":"https://crypto.news/hacken-bridge-exploited-for-250k-hai-token-following-private-key-leak/","name":"crypto.news","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2025/06/21/hacken-bridge-hacked-900m-hai-minted-via-stolen-private-key/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://www.fxleaders.com/news/2025/06/23/cybersecurity-firm-hacken-suffers-98-token-crash-after-private-key-compromise/","name":"fxleaders.com","type":"other","credibility":3},{"url":"https://etherscan.io/token/0x05Fb86775Fd5c16290f1E838F5caaa7342bD9a63","name":"etherscan.io","type":"other","credibility":3},{"url":"https://bscscan.com/token/0xaa9e582e5751d703f85912903bacaddfed26484c","name":"bscscan.com","type":"other","credibility":3}],"severity":"medium"},{"content":"CEO Dyma Budorin publicly accepted full responsibility for the incident, stating on X (formerly Twitter): 'Responsibility is on me. I didn't implement multisig bridge infra 5 years ago. I understood the risk, but delayed bridge restructuring due to not unimportant reasons.' This admission confirmed that the company's leadership was aware of the architectural risk — single-key control over token minting — but deferred remediation for an extended period. The exploited private key vulnerability had existed since the bridge's original deployment. The incident occurred precisely as Hacken was in the process of redesigning its bridge architecture; the key was allegedly exposed during this migration procedure. Budorin stated the breach was isolated to the bridge minting key and that 'core infrastructure remained secure and unaffected.' He also noted that the incident had primarily damaged the company's reputation rather than its operational capacity. Community members and observers noted the deep irony of a cybersecurity audit firm — whose annual reports routinely identify access control failures as the leading cause of crypto losses — maintaining a single-key minting architecture on its own token for over five years.","heading":"Root Cause: Five Years of Deferred Multisig Implementation","sources":[{"url":"https://www.analyticsinsight.net/news/250k-vanishes-in-seconds-hacken-token-crashes-99-after-shocking-minting-exploit","name":"analyticsinsight.net","type":"other","credibility":3},{"url":"https://www.theblock.co/post/359097/hacken-cites-human-error-after-private-key-leak-triggers-5-million-crash-in-hai-value","name":"theblock.co","type":"other","credibility":3},{"url":"https://web.ourcryptotalk.com/news/hai-token-crash-how-hacken-a-web3-security-firm-got-hacked","name":"web.ourcryptotalk.com","type":"other","credibility":3},{"url":"https://hacken.io/insights/2024-security-report/","name":"hacken.io","type":"other","credibility":3}],"severity":"medium"},{"content":"On-chain investigator ZachXBT flagged the Hacken Token (HAI) incident, contributing to the entity's current elevated risk classification. The flagging aligns with ZachXBT's established pattern of alerting the crypto community to significant token security failures, rug vectors, and infrastructure compromises regardless of a project's stated reputation. The community reaction was notable for focusing on the reputational contradiction: Hacken publishes annual Web3 security reports identifying access control failures as the primary driver of industry-wide losses (accounting for 75–78% of total crypto hack losses in 2024, per Hacken's own research), yet the company failed to implement the most basic access control best practice — multisignature key management — on its own token's minting infrastructure. Following the exploit, scam actors launched unauthorized HAI airdrop campaigns across Telegram, Discord, and social media, attempting to exploit user uncertainty. Hacken explicitly warned that no official HAI airdrop was active and that all airdrop claims were phishing attempts.","heading":"ZachXBT Flagging and Community Response","sources":[{"url":"https://transnetinc.com/hacken-token-hai-airdrop-official-status-security-breach-details-scam-warning","name":"transnetinc.com","type":"other","credibility":3},{"url":"https://hacken.io/insights/2024-security-report/","name":"hacken.io","type":"other","credibility":3},{"url":"https://www.coingabbar.com/en/crypto-currency-news/hacken-token-plunge-99-after-private-key-hack-what-next-for-hai","name":"coingabbar.com","type":"other","credibility":3},{"url":"https://www.hokanews.com/2025/06/hacken-hacked-cybersecurity-giants-250k.html","name":"hokanews.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, Hacken published an infrastructure update on June 24, 2025 outlining a full token rebuild. The new HAI architecture migrates to LayerZero's Omnichain Fungible Token (OFT) standard, deployed across Ethereum, BSC, and Base, replacing all custom bridge code with LayerZero's protocol. The new contract introduces multi-signature governance (replacing single-key control), pausable emergency controls, and an address blacklist function. A pre-incident snapshot was taken at BSC block 51800329 and ETH block 22747526 to establish legitimate holder balances. All holders at the snapshot receive a 1:1 migration of their HAI balance. Tokens purchased after the hack on Ethereum and BNB Chain were excluded from the tokenomics update. The claim window is six months via Merkle proof through the official hAI App; Hacken explicitly stated no web-based claiming mechanism exists in order to prevent phishing. The contract deployment targeted early July 2025, with the hAI App update and liquidity pool reboot targeted for July 7–11, 2025. In the longer term, CEO Budorin stated plans to transition HAI into a regulated security token representing company equity, combining token utility with shareholder rights.","heading":"Recovery Plan: LayerZero OFT Migration","sources":[{"url":"https://hackenclub.medium.com/hai-infrastructure-update-861161892330","name":"hackenclub.medium.com","type":"other","credibility":3},{"url":"https://x.com/hackenclub/status/1937577045627929011","name":"x.com","type":"other","credibility":3},{"url":"https://hai.hacken.io/","name":"hai.hacken.io","type":"other","credibility":3}],"severity":"medium"},{"content":"The June 2025 incident raises several structural concerns relevant to holders and counterparties of the HAI token. First, the token's primary value proposition — representing equity in a leading cybersecurity firm — was materially undermined by the firm's failure to apply standard security practices to its own infrastructure, a fact acknowledged by the CEO. Second, the five-year delay in implementing multisig despite known risk indicates governance dysfunction at the token infrastructure level, separate from the company's core auditing operations. Third, the proposed conversion to a regulated security token introduces significant jurisdictional and compliance risk with uncertain timelines. Fourth, while direct attacker losses were capped at approximately $253,000 due to liquidity constraints, token holders experienced market cap losses exceeding $5 million on a mark-to-market basis. Hacken's core auditing business — clients include the Ethereum Foundation, Bybit, and MetaMask — operates independently from the HAI token and has not been reported as compromised. The company's 2024 security report documented 78% of total crypto hack losses stemming from access control failures, the precise vulnerability class that enabled this incident.","heading":"Reputational and Structural Risk Assessment","sources":[{"url":"https://crypto.news/hacken-bridge-exploited-for-250k-hai-token-following-private-key-leak/","name":"crypto.news","type":"other","credibility":3},{"url":"https://www.theblock.co/post/359097/hacken-cites-human-error-after-private-key-leak-triggers-5-million-crash-in-hai-value","name":"theblock.co","type":"other","credibility":3},{"url":"https://hacken.io/insights/2024-security-report/","name":"hacken.io","type":"other","credibility":3},{"url":"https://www.fxleaders.com/news/2025/06/23/cybersecurity-firm-hacken-suffers-98-token-crash-after-private-key-compromise/","name":"fxleaders.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2017","event":"Hacken founded in Ukraine by Dyma Budorin and Yevheniia Broshevan as a blockchain cybersecurity firm.","source":"","date_original":"2017-01-01"},{"date":"2024-03-24","event":"HAI token reaches all-time high of approximately $0.4659.","source":""},{"date":"2025-06-20","event":"Private key associated with HAI minting role on Ethereum and BNB Chain compromised during bridge infrastructure migration.","source":""},{"date":"2025-06-21","event":"Attacker mints approximately 900 million HAI tokens and dumps them on BSC DEXs, realizing approximately $253,000 in proceeds. HAI price collapses 98-99% from $0.015 to $0.000056.","source":""},{"date":"2025-06-21","event":"Hacken revokes minter access on compromised key and pauses bridge transactions on Ethereum and BNB Chain.","source":""},{"date":"2025-06-23","event":"CEO Dyma Budorin issues public statement accepting responsibility, acknowledging five-year deferral of multisig implementation. The Block, CoinTelegraph, and crypto.news publish coverage.","source":""},{"date":"2025-06-24","event":"Hacken publishes infrastructure update announcing LayerZero OFT migration and pre-incident snapshot taken at BSC block 51800329 and ETH block 22747526.","source":""},{"date":"2025-06-24","event":"ZachXBT flags the Hacken Token incident, contributing to elevated risk classification on AVOID.NET.","source":""},{"date":"2025-07-07","event":"Target date for hAI App release enabling 1:1 token claims via Merkle proof under new LayerZero OFT contract.","source":""},{"date":"2025-07-11","event":"Target date for liquidity pool reinitialization on new HAI contract across Ethereum, BSC, and Base.","source":""}],"sources_used":[{"url":"https://hacken.io/about/","name":"hacken.io","type":"other","archive_url":"http://web.archive.org/web/20260731211629/https://hacken.io/about/","credibility":3,"archive_timestamp":"2026-07-31T21:16:29+00:00"},{"url":"https://crypto.news/hacken-bridge-exploited-for-250k-hai-token-following-private-key-leak/","name":"crypto.news","type":"other","archive_url":"http://web.archive.org/web/20260830072210/https://crypto.news/hacken-bridge-exploited-for-250k-hai-token-following-private-key-leak/","credibility":3,"archive_timestamp":"2026-08-30T07:22:10+00:00"},{"url":"https://www.coingecko.com/en/coins/hacken","name":"coingecko.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://coinmarketcap.com/currencies/hackenai/","name":"coinmarketcap.com","type":"other","archive_url":"http://web.archive.org/web/20260529170319/https://coinmarketcap.com/currencies/hackenai/","credibility":3,"archive_timestamp":"2026-05-29T17:03:19+00:00"},{"url":"https://www.cryptotimes.io/2025/06/21/hacken-bridge-hacked-900m-hai-minted-via-stolen-private-key/","name":"cryptotimes.io","type":"other","archive_url":"https://web.archive.org/web/20260829122107/https://www.cryptotimes.io/2025/06/21/hacken-bridge-hacked-900m-hai-minted-via-stolen-private-key/","credibility":3,"archive_timestamp":"2026-08-29T12:21:07+00:00"},{"url":"https://www.fxleaders.com/news/2025/06/23/cybersecurity-firm-hacken-suffers-98-token-crash-after-private-key-compromise/","name":"fxleaders.com","type":"other","archive_url":"http://web.archive.org/web/20260511201746/https://www.fxleaders.com/news/2025/06/23/cybersecurity-firm-hacken-suffers-98-token-crash-after-private-key-compromise/","credibility":3,"archive_timestamp":"2026-05-11T20:17:46+00:00"},{"url":"https://etherscan.io/token/0x05Fb86775Fd5c16290f1E838F5caaa7342bD9a63","name":"etherscan.io","type":"other","archive_url":"https://web.archive.org/web/20260829032555/https://etherscan.io/token/0x05Fb86775Fd5c16290f1E838F5caaa7342bD9a63","credibility":3,"archive_timestamp":"2026-08-29T03:25:55+00:00"},{"url":"https://bscscan.com/token/0xaa9e582e5751d703f85912903bacaddfed26484c","name":"bscscan.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.analyticsinsight.net/news/250k-vanishes-in-seconds-hacken-token-crashes-99-after-shocking-minting-exploit","name":"analyticsinsight.net","type":"other","archive_url":"https://web.archive.org/web/20260829083117/https://www.analyticsinsight.net/news/250k-vanishes-in-seconds-hacken-token-crashes-99-after-shocking-minting-exploit","credibility":3,"archive_timestamp":"2026-08-29T08:31:17+00:00"},{"url":"https://www.theblock.co/post/359097/hacken-cites-human-error-after-private-key-leak-triggers-5-million-crash-in-hai-value","name":"theblock.co","type":"other","archive_url":"http://web.archive.org/web/20260511093037/https://www.theblock.co/post/359097/hacken-cites-human-error-after-private-key-leak-triggers-5-million-crash-in-hai-value","credibility":3,"archive_timestamp":"2026-05-11T09:30:37+00:00"},{"url":"https://web.ourcryptotalk.com/news/hai-token-crash-how-hacken-a-web3-security-firm-got-hacked","name":"web.ourcryptotalk.com","type":"other","archive_url":"https://web.archive.org/web/20260829042142/https://ourcryptotalk.com/blog/hai-token-crash-how-hacken-a-web3-security-firm-got-hacked","credibility":3,"archive_timestamp":"2026-08-29T04:21:42+00:00"},{"url":"https://hacken.io/insights/2024-security-report/","name":"hacken.io","type":"other","archive_url":"http://web.archive.org/web/20260414150028/https://hacken.io/insights/2024-security-report/","credibility":3,"archive_timestamp":"2026-04-14T15:00:28+00:00"},{"url":"https://transnetinc.com/hacken-token-hai-airdrop-official-status-security-breach-details-scam-warning","name":"transnetinc.com","type":"other","archive_url":"http://web.archive.org/web/20260611042827/https://transnetinc.com/hacken-token-hai-airdrop-official-status-security-breach-details-scam-warning","credibility":3,"archive_timestamp":"2026-06-11T04:28:27+00:00"},{"url":"https://www.coingabbar.com/en/crypto-currency-news/hacken-token-plunge-99-after-private-key-hack-what-next-for-hai","name":"coingabbar.com","type":"other","archive_url":"http://web.archive.org/web/20260829045401/https://www.coingabbar.com/en/crypto-currency-news/hacken-token-plunge-99-after-private-key-hack-what-next-for-hai","credibility":3,"archive_timestamp":"2026-08-29T04:54:01+00:00"},{"url":"https://www.hokanews.com/2025/06/hacken-hacked-cybersecurity-giants-250k.html","name":"hokanews.com","type":"other","archive_url":"https://web.archive.org/web/20260829050337/https://www.hokanews.com/2025/06/hacken-hacked-cybersecurity-giants-250k.html","credibility":3,"archive_timestamp":"2026-08-29T05:03:37+00:00"},{"url":"https://hackenclub.medium.com/hai-infrastructure-update-861161892330","name":"hackenclub.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://x.com/hackenclub/status/1937577045627929011","name":"x.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://hai.hacken.io/","name":"hai.hacken.io","type":"other","archive_url":"http://web.archive.org/web/20260808075636/https://hai.hacken.io/","credibility":3,"archive_timestamp":"2026-08-08T07:56:36+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:22.827606+00:00","updated_at":"2026-08-30T12:05:01.049984+00:00"}}