Summary
Hedgey is a token vesting, lockup, and claims protocol that served over 100 on-chain projects before suffering a critical smart contract exploit on April 19, 2024, resulting in the theft of approximately $44.7 million across Ethereum and Arbitrum. The vulnerability — a missing input validation check in the ClaimCampaigns.sol contract — was present despite two prior audits by ConsenSys Diligence. No confirmed recovery of stolen funds has been reported; Hedgey was subsequently acquired by Anchorage Digital in late 2025.
Connected Entities
1 entitiesTimeline(6 events)
2023-06-01
ConsenSys Diligence completes second audit of Hedgey contracts, including the re-audit commissioned for Arbitrum DAO onboarding; vulnerable ClaimCampaigns.sol flaw goes undetected.
2024-04-19
Exploit begins at ~07:06 UTC. Attacker uses $1.3M Balancer flash loan to abuse createLockedCampaign input validation gap in ClaimCampaigns.sol. $2.1M drained on Ethereum; $42.6M in BONUS tokens drained on Arbitrum. Secondary copycat attacker linked to Unizen exploit also strikes on Ethereum. Total loss: ~$44.7M.
2024-04-19
Hedgey team disables new claims creation, engages SEAL 911, contacts Gate.io and Bybit to freeze attacker-linked deposits, and sends on-chain message to attacker requesting return of funds.
2024-04-19
CUBE3.AI publishes postmortem confirming real-time detection of the malicious transaction; CertiK and Halborn publish independent on-chain analyses identifying attacker addresses and laundering behavior.
2024-04-20
Official post-mortem published by Hedgey team via Medium, confirming 23 of 60 active campaigns were impacted, vesting/lockup contracts were unaffected, and law enforcement coordination was underway.
2025-12-16
Anchorage Digital announces acquisition of Hedgey, integrating the token vesting tooling into a full-stack institutional token lifecycle management product. Deal terms undisclosed.
Decision Log
- hash: C5tV7vA4UUsdVjbPiJ4ptjWbox71x1LJLhKnsGdi3hsf
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:33 AM
last updated: 5/20/2026, 3:26:58 PM
avoid.net — verified advice for a post-truth world