Skip to main content
AVOID.NET
Hacken Token2 decisions on this page

Audit log

Every state-changing event for Hacken Token: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-05-29 17:31:46Z
    Score: ?? (no score change)
    anchoranchored
    chain
    mainnet-betaslot 422,984,273
    sig
    3pzNb5jYreqW…vg9GpFj6explorer ↗
    hash
    4Gg5rKzdreEb…J2kdKmxjsha256 → base58
    verifying row…full verify ↗
    canonical bytes (6213 B) ▸
    {"actor":"system:backfill","investigation_id":"8be993d6-1435-4c2e-9d86-fe00f9f22a62","kind":"publish","page_slug":"hacken-token","published_at":"2026-05-29T17:31:46.201Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Hacken Token","sections":[{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://hacken.io/about/","type":"other","url":""},{"credibility":3,"name":"https://crypto.news/hacken-bridge-exploited-for-250k-hai-token-following-private-key-leak/","type":"other","url":""},{"credibility":3,"name":"https://www.coingecko.com/en/coins/hacken","type":"other","url":""},{"credibility":3,"name":"https://coinmarketcap.com/currencies/hackenai/","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://crypto.news/hacken-bridge-exploited-for-250k-hai-token-following-private-key-leak/","type":"other","url":""},{"credibility":3,"name":"https://www.cryptotimes.io/2025/06/21/hacken-bridge-hacked-900m-hai-minted-via-stolen-private-key/","type":"other","url":""},{"credibility":3,"name":"https://www.fxleaders.com/news/2025/06/23/cybersecurity-firm-hacken-suffers-98-token-crash-after-private-key-compromise/","type":"other","url":""},{"credibility":3,"name":"https://etherscan.io/token/0x05Fb86775Fd5c16290f1E838F5caaa7342bD9a63","type":"other","url":""},{"credibility":3,"name":"https://bscscan.com/token/0xaa9e582e5751d703f85912903bacaddfed26484c","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.analyticsinsight.net/news/250k-vanishes-in-seconds-hacken-token-crashes-99-after-shocking-minting-exploit","type":"other","url":""},{"credibility":3,"name":"https://www.theblock.co/post/359097/hacken-cites-human-error-after-private-key-leak-triggers-5-million-crash-in-hai-value","type":"other","url":""},{"credibility":3,"name":"https://web.ourcryptotalk.com/news/hai-token-crash-how-hacken-a-web3-security-firm-got-hacked","type":"other","url":""},{"credibility":3,"name":"https://hacken.io/insights/2024-security-report/","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://transnetinc.com/hacken-token-hai-airdrop-official-status-security-breach-details-scam-warning","type":"other","url":""},{"credibility":3,"name":"https://hacken.io/insights/2024-security-report/","type":"other","url":""},{"credibility":3,"name":"https://www.coingabbar.com/en/crypto-currency-news/hacken-token-plunge-99-after-private-key-hack-what-next-for-hai","type":"other","url":""},{"credibility":3,"name":"https://www.hokanews.com/2025/06/hacken-hacked-cybersecurity-giants-250k.html","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://hackenclub.medium.com/hai-infrastructure-update-861161892330","type":"other","url":""},{"credibility":3,"name":"https://x.com/hackenclub/status/1937577045627929011","type":"other","url":""},{"credibility":3,"name":"https://hai.hacken.io/","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://crypto.news/hacken-bridge-exploited-for-250k-hai-token-following-private-key-leak/","type":"other","url":""},{"credibility":3,"name":"https://www.theblock.co/post/359097/hacken-cites-human-error-after-private-key-leak-triggers-5-million-crash-in-hai-value","type":"other","url":""},{"credibility":3,"name":"https://hacken.io/insights/2024-security-report/","type":"other","url":""},{"credibility":3,"name":"https://www.fxleaders.com/news/2025/06/23/cybersecurity-firm-hacken-suffers-98-token-crash-after-private-key-compromise/","type":"other","url":""}]}],"sources_used":[],"summary":"Hacken Token (HAI) is the native utility token of Hacken, a Ukrainian-founded Web3 cybersecurity company established in 2017 that audits smart contracts and blockchain infrastructure for over 1,500 clients worldwide. In June 2025, a private key controlling HAI minting privileges was compromised during a bridge infrastructure migration, allowing an attacker to mint approximately 900 million tokens and dump roughly $253,000 worth on decentralized exchanges, causing a near-99% price collapse. The incident drew industry-wide attention due to its irony — a company whose business model is built on securing others' blockchain infrastructure had maintained a single-key minting architecture for over five years without multisig protection.","timeline":[{"date":"2017-01-01","event":"Hacken founded in Ukraine by Dyma Budorin and Yevheniia Broshevan as a blockchain cybersecurity firm.","source":""},{"date":"2024-03-24","event":"HAI token reaches all-time high of approximately $0.4659.","source":""},{"date":"2025-06-20","event":"Private key associated with HAI minting role on Ethereum and BNB Chain compromised during bridge infrastructure migration.","source":""},{"date":"2025-06-21","event":"Attacker mints approximately 900 million HAI tokens and dumps them on BSC DEXs, realizing approximately $253,000 in proceeds. HAI price collapses 98-99% from $0.015 to $0.000056.","source":""},{"date":"2025-06-21","event":"Hacken revokes minter access on compromised key and pauses bridge transactions on Ethereum and BNB Chain.","source":""},{"date":"2025-06-23","event":"CEO Dyma Budorin issues public statement accepting responsibility, acknowledging five-year deferral of multisig implementation. The Block, CoinTelegraph, and crypto.news publish coverage.","source":""},{"date":"2025-06-24","event":"Hacken publishes infrastructure update announcing LayerZero OFT migration and pre-incident snapshot taken at BSC block 51800329 and ETH block 22747526.","source":""},{"date":"2025-06-24","event":"ZachXBT flags the Hacken Token incident, contributing to elevated risk classification on AVOID.NET.","source":""},{"date":"2025-07-07","event":"Target date for hAI App release enabling 1:1 token claims via Merkle proof under new LayerZero OFT contract.","source":""},{"date":"2025-07-11","event":"Target date for liquidity pool reinitialization on new HAI contract across Ethereum, BSC, and Base.","source":""}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 05200e09-6506-4711-afd1-4158d4a611ce
  2. #2reviewby reviewerreviewer
    2026-08-18 17:40:30Z
    Score: 4242 (no score change)
    The page's central narrative — a private key compromised during a bridge migration, ~900M HAI minted and ~$250K dumped, a near-99% price collapse, and a CEO admission of a five-year multisig deferral — is well corroborated by multiple independent tier-1/tier-2 outlets and Hacken's own public statements. Two defects were found: the ATH timeline entry conflates the true all-time-high price (reached April 2021) with a much lower March 2024 secondary peak, and the ZachXBT/AVOID.NET risk-classification claim is uncited and unverifiable. The most significant issue is structural, not factual: every section in this snapshot has empty heading/content fields, leaving only source-list clusters with no prose for a reader or reviewer to check claims against — this is a data/rendering defect that should be corrected independent of the score question. No unhedged criminal allegations were found; the page consistently and correctly frames Hacken as the victim of a security failure rather than a perpetrator of fraud.
    anchoranchored
    chain
    mainnet-betaslot 443,508,383
    sig
    2Ewuw2g5or6R…L74crXTsexplorer ↗
    hash
    5sYhrYCZ2YZg…BamMfpEGsha256 → base58
    verifying row…full verify ↗
    canonical bytes (1363 B) ▸
    {"actor":"reviewer","decided_at":"2026-08-18T17:40:30.758Z","decision":"review","investigation_id":"8be993d6-1435-4c2e-9d86-fe00f9f22a62","new_score":42,"page_slug":"hacken-token","prev_score":42,"reason":"The page's central narrative — a private key compromised during a bridge migration, ~900M HAI minted and ~$250K dumped, a near-99% price collapse, and a CEO admission of a five-year multisig deferral — is well corroborated by multiple independent tier-1/tier-2 outlets and Hacken's own public statements. Two defects were found: the ATH timeline entry conflates the true all-time-high price (reached April 2021) with a much lower March 2024 secondary peak, and the ZachXBT/AVOID.NET risk-classification claim is uncited and unverifiable. The most significant issue is structural, not factual: every section in this snapshot has empty heading/content fields, leaving only source-list clusters with no prose for a reader or reviewer to check claims against — this is a data/rendering defect that should be corrected independent of the score question. No unhedged criminal allegations were found; the page consistently and correctly frames Hacken as the victim of a security failure rather than a perpetrator of fraud.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 5f93bdf4-4747-4d90-bc58-575db61b48d7
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.