{"investigation":{"slug":"hedgey","entity_name":"Hedgey","trust_score":18,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"Hedgey is a token vesting, lockup, and claims protocol that served over 100 on-chain projects before suffering a critical smart contract exploit on April 19, 2024, resulting in the theft of approximately $44.7 million across Ethereum and Arbitrum. The vulnerability — a missing input validation check in the ClaimCampaigns.sol contract — was present despite two prior audits by ConsenSys Diligence. No confirmed recovery of stolen funds has been reported; Hedgey was subsequently acquired by Anchorage Digital in late 2025.","sections":[{"content":"Hedgey Finance describes itself as a token infrastructure platform providing vesting schedules, token lockups, and claims campaigns for on-chain teams. The protocol was used by over 100 projects, including integrations with Arbitrum DAO. Its primary smart contract suite includes ClaimCampaigns.sol, which enables teams to distribute tokens to claimants under configurable lockup conditions. Prior to the April 2024 exploit, the protocol had undergone two separate audits by ConsenSys Diligence — an initial audit during early development and a re-audit commissioned when onboarding Arbitrum DAO as a client. A Hacken audit also appears in public records. Despite this review history, a critical business-logic vulnerability went undetected across all audits. In December 2025, Hedgey was acquired by Anchorage Digital, a federally chartered crypto bank, which integrated Hedgey's tooling into a full-stack token lifecycle management product.","heading":"Background","sources":[{"url":"https://medium.com/hedgey/hedgey-exploit-post-mortem-784e9860fd8d","name":"","type":"other","credibility":3},{"url":"https://olympix.ai/blog/the-44m-hedgey-finance-exploit-what-went-wrong-and-how-olympix-could-have-prevented-it","name":"","type":"other","credibility":3},{"url":"https://www.anchorage.com/insights/anchorage-digital-launches-full-stack-token-management-solution-to-power-next-generation-protocol-growth","name":"","type":"other","credibility":3},{"url":"https://hacken.io/audits/hedgey-finance/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On April 19, 2024 at approximately 07:06:47 UTC, an attacker exploited a critical input validation flaw in Hedgey's ClaimCampaigns.sol contract. The vulnerable function, createLockedCampaign, lacked validation on the claimLockup parameter — specifically the tokenLocker field of the ClaimLockup struct. By supplying a malicious contract address as the tokenLocker, the attacker caused the function to grant an ERC-20 spend allowance for the entire campaign amount to their own contract. The attacker then immediately called cancelCampaign, which returned tokens to the tokenLocker address but critically did not revoke the ERC-20 approval. The attacker's contract was then able to drain the full approved token balance. A flash loan of $1.3 million USDC from Balancer was used to fund the initial campaign creation, making the attack self-financing. Losses were recorded across multiple chains: approximately $2.1 million on Ethereum (1.3M USDC plus NOBL and MASA tokens); approximately $42.6 million on Arbitrum (78,148,820 BONUS tokens); and smaller amounts on Fantom ($170K), BSC ($4,600), Polygon ($800), and Shimmer Network ($500). A secondary copycat exploiter — linked by CertiK analysis to a prior Unizen exploit — replicated the attack on Ethereum after the initial breach became public. Of 60 active claim campaigns at the time, 23 suffered fund losses. The team's vesting and lockup contracts were unaffected; only ClaimCampaigns.sol was vulnerable. Despite being audited twice by ConsenSys Diligence, the flaw — a dangerous interaction between two individually benign functions — was missed in both reviews.","heading":"The $44.7M Exploit","sources":[{"url":"https://medium.com/hedgey/hedgey-exploit-post-mortem-784e9860fd8d","name":"","type":"other","credibility":3},{"url":"https://rekt.news/hedgey-finance-rekt","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-hedgey-finance-hack-april-2024","name":"","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/hedgey-protocol-44-million-exploit","name":"","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/defi-protocol-hedgey-finance-suffers-usd44m-hack","name":"","type":"other","credibility":3},{"url":"https://immunebytes.com/blog/hedgey-finance-exploit-april-19-2024-detailed-analysis/","name":"","type":"other","credibility":3},{"url":"https://blog.cube3.ai/2024/04/19/hedgey-finance-hack-flashloan-cube3-postmortem-report/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"CertiK and Rekt News published attacker wallet addresses identified on-chain. The primary Ethereum attacker address is 0xDed2b1a426E1b7d415A40Bcad44e98F47181dda2, which stole 1,303,910 USDC. The attacker's approval contract on Ethereum is 0xC793113F1548B97E37c409f39244EE44241bF2b3. The Arbitrum attacker was funded via the Axelar bridge from Ethereum EOA 0xC7241E27Ee4B8D32b59a10E848B48530047a8c5b — an address CertiK noted had previously been linked to an exploit on Kardia Bridge resulting in a loss of 10.5 WETH. The primary exploit transaction hash on Ethereum is 0xa17fdb804728f226fcd10e78eae5247abd984e0f03301312315b89cae25aa517. Post-exploit, the Arbitrum attacker retained approximately 76.8 million BONUS tokens in the primary wallet, transferred 200,000 BONUS tokens to a Bybit exchange deposit address, and distributed approximately 900,000 BONUS tokens across additional wallets. Transfers to Bybit and links to FixedFloat were noted as indicative of potential laundering activity. CUBE3.AI reported that its automated monitoring system flagged the malicious transaction in real time before the full scale of the exploit unfolded, but no automated protection was in place to halt execution. The Hedgey team sent an on-chain message to the attacker — described by Rekt News as including a 'well done' commendation — in an attempt to treat the incident as a white hat discovery and negotiate a return of funds.","heading":"On-Chain Evidence","sources":[{"url":"https://www.certik.com/resources/blog/hedgey-finance-incident-analysis","name":"","type":"other","credibility":3},{"url":"https://rekt.news/hedgey-finance-rekt","name":"","type":"other","credibility":3},{"url":"https://blog.cube3.ai/2024/04/19/hedgey-finance-hack-flashloan-cube3-postmortem-report/","name":"","type":"other","credibility":3},{"url":"https://beincrypto.com/hedgey-incurs-loss-in-crypto-hack/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Immediately following the exploit, the Hedgey team disabled new claims creation, engaged SEAL 911 (a DeFi incident response group), and coordinated with centralized exchanges Gate.io and Bybit to freeze deposits linked to the attacker's addresses. An on-chain message was sent to the exploiter framing the incident as a potential white hat discovery and soliciting fund return. The team stated in its official post-mortem that it was cooperating with law enforcement. No confirmed return of funds has been publicly documented as of the time of this investigation. One impacted project successfully reissued tokens to its community through a new, patched contract. In its post-mortem, Hedgey committed to conducting four additional smart contract audits and engaging dedicated security experts going forward. The protocol's vesting and lockup contracts — distinct from the exploited ClaimCampaigns.sol — were confirmed unaffected and remained operational. Hedgey's GitHub repository shows continued contract development activity through at least February 2025.","heading":"Recovery Efforts","sources":[{"url":"https://medium.com/hedgey/hedgey-exploit-post-mortem-784e9860fd8d","name":"","type":"other","credibility":3},{"url":"https://crypto.news/hedgey-finance-hacked-for-44-7m-on-arbitrum-ethereum/","name":"","type":"other","credibility":3},{"url":"https://cryptobriefing.com/hedgey-finance-flash-loan-exploit/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Hedgey presents several compounding risk factors. First, the protocol suffered one of the largest DeFi exploits of Q2 2024, with approximately $44.7 million stolen — funds that remained unrecovered as of public reporting. Second, the vulnerability existed in code that had been reviewed twice by a Tier 1 audit firm (ConsenSys Diligence), demonstrating that audit coverage does not guarantee contract safety, particularly for business-logic flaws involving function interaction. Third, the attacker's Arbitrum-linked address was connected to a prior bridge exploit, suggesting the attack was conducted by experienced adversaries rather than opportunistic actors. Fourth, post-exploit laundering behavior — including transfers to Bybit and links to FixedFloat — reduced the probability of fund recovery via exchange freezes alone. Fifth, the incident affected 23 of 60 active campaigns at the time, directly harming downstream protocol users and token holders who had no direct relationship with Hedgey's contracts. The subsequent acquisition by Anchorage Digital (announced December 2025) represents a material change in the risk profile for new users, as institutional stewardship may improve security practices; however, the pre-acquisition exploit losses were not compensated to victims from publicly available information. Projects currently relying on Hedgey contracts should verify which contract version they are using and confirm it is not the unpatched ClaimCampaigns.sol variant.","heading":"Risk Assessment","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-hedgey-finance-hack-april-2024","name":"","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/hedgey-finance-incident-analysis","name":"","type":"other","credibility":3},{"url":"https://olympix.ai/blog/the-44m-hedgey-finance-exploit-what-went-wrong-and-how-olympix-could-have-prevented-it","name":"","type":"other","credibility":3},{"url":"https://www.anchorage.com/insights/anchorage-digital-launches-full-stack-token-management-solution-to-power-next-generation-protocol-growth","name":"","type":"other","credibility":3},{"url":"https://tracxn.com/d/insights/merger-acquisition-deals-brief/anchorage-digital-acquires-hedgey/__4KzVvRDuMqoyMDEVEi4vHYqWxSLLQwKCBLHGXoHoelE","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023-06","event":"ConsenSys Diligence completes second audit of Hedgey contracts, including the re-audit commissioned for Arbitrum DAO onboarding; vulnerable ClaimCampaigns.sol flaw goes undetected.","source":"","date_original":"2023-06-01"},{"date":"2024-04-19","event":"Exploit begins at ~07:06 UTC. Attacker uses $1.3M Balancer flash loan to abuse createLockedCampaign input validation gap in ClaimCampaigns.sol. $2.1M drained on Ethereum; $42.6M in BONUS tokens drained on Arbitrum. Secondary copycat attacker linked to Unizen exploit also strikes on Ethereum. Total loss: ~$44.7M.","source":""},{"date":"2024-04-19","event":"Hedgey team disables new claims creation, engages SEAL 911, contacts Gate.io and Bybit to freeze attacker-linked deposits, and sends on-chain message to attacker requesting return of funds.","source":""},{"date":"2024-04-19","event":"CUBE3.AI publishes postmortem confirming real-time detection of the malicious transaction; CertiK and Halborn publish independent on-chain analyses identifying attacker addresses and laundering behavior.","source":""},{"date":"2024-04-20","event":"Official post-mortem published by Hedgey team via Medium, confirming 23 of 60 active campaigns were impacted, vesting/lockup contracts were unaffected, and law enforcement coordination was underway.","source":""},{"date":"2025-12-16","event":"Anchorage Digital announces acquisition of Hedgey, integrating the token vesting tooling into a full-stack institutional token lifecycle management product. Deal terms undisclosed.","source":""}],"sources_used":[{"url":"https://medium.com/hedgey/hedgey-exploit-post-mortem-784e9860fd8d","name":"","type":"other","archive_url":"http://web.archive.org/web/20260725143809/https://medium.com/hedgey/hedgey-exploit-post-mortem-784e9860fd8d","credibility":3,"archive_timestamp":"2026-07-25T14:38:09+00:00"},{"url":"https://olympix.ai/blog/the-44m-hedgey-finance-exploit-what-went-wrong-and-how-olympix-could-have-prevented-it","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.anchorage.com/insights/anchorage-digital-launches-full-stack-token-management-solution-to-power-next-generation-protocol-growth","name":"","type":"other","archive_url":"http://web.archive.org/web/20260608234124/https://www.anchorage.com/insights/anchorage-digital-launches-full-stack-token-management-solution-to-power-next-generation-protocol-growth","credibility":3,"archive_timestamp":"2026-06-08T23:41:24+00:00"},{"url":"https://hacken.io/audits/hedgey-finance/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260520135541/https://hacken.io/audits/hedgey-finance/","credibility":3,"archive_timestamp":"2026-05-20T13:55:41+00:00"},{"url":"https://rekt.news/hedgey-finance-rekt","name":"","type":"other","archive_url":"http://web.archive.org/web/20260415155826/https://rekt.news/hedgey-finance-rekt","credibility":3,"archive_timestamp":"2026-04-15T15:58:26+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-hedgey-finance-hack-april-2024","name":"","type":"other","archive_url":"http://web.archive.org/web/20260414125504/https://www.halborn.com/blog/post/explained-the-hedgey-finance-hack-april-2024","credibility":3,"archive_timestamp":"2026-04-14T12:55:04+00:00"},{"url":"https://cointelegraph.com/news/hedgey-protocol-44-million-exploit","name":"","type":"other","archive_url":"http://web.archive.org/web/20260725201549/https://cointelegraph.com/news/hedgey-protocol-44-million-exploit","credibility":3,"archive_timestamp":"2026-07-25T20:15:49+00:00"},{"url":"https://thedefiant.io/news/defi/defi-protocol-hedgey-finance-suffers-usd44m-hack","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://immunebytes.com/blog/hedgey-finance-exploit-april-19-2024-detailed-analysis/","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://blog.cube3.ai/2024/04/19/hedgey-finance-hack-flashloan-cube3-postmortem-report/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260112161409/https://blog.cube3.ai/2024/04/19/hedgey-finance-hack-flashloan-cube3-postmortem-report/","credibility":3,"archive_timestamp":"2026-01-12T16:14:09+00:00"},{"url":"https://www.certik.com/resources/blog/hedgey-finance-incident-analysis","name":"","type":"other","archive_url":"http://web.archive.org/web/20251208111703/https://www.certik.com/resources/blog/hedgey-finance-incident-analysis","credibility":3,"archive_timestamp":"2025-12-08T11:17:03+00:00"},{"url":"https://beincrypto.com/hedgey-incurs-loss-in-crypto-hack/","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://crypto.news/hedgey-finance-hacked-for-44-7m-on-arbitrum-ethereum/","name":"","type":"other","archive_url":"http://web.archive.org/web/20251213220505/https://crypto.news/hedgey-finance-hacked-for-44-7m-on-arbitrum-ethereum/","credibility":3,"archive_timestamp":"2025-12-13T22:05:05+00:00"},{"url":"https://cryptobriefing.com/hedgey-finance-flash-loan-exploit/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260211085758/https://cryptobriefing.com/hedgey-finance-flash-loan-exploit/","credibility":3,"archive_timestamp":"2026-02-11T08:57:58+00:00"},{"url":"https://tracxn.com/d/insights/merger-acquisition-deals-brief/anchorage-digital-acquires-hedgey/__4KzVvRDuMqoyMDEVEi4vHYqWxSLLQwKCBLHGXoHoelE","name":"","type":"other","archive_url":"https://web.archive.org/web/20260830003050/https://tracxn.com/d/insights/merger-acquisition-deals-brief/anchorage-digital-acquires-hedgey/__4KzVvRDuMqoyMDEVEi4vHYqWxSLLQwKCBLHGXoHoelE","credibility":3,"archive_timestamp":"2026-08-30T00:30:50+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:33.422136+00:00","updated_at":"2026-08-30T01:16:27.581587+00:00"}}