0xflorent found that an admin function on the contract, restricted to HongCoin’s multisig wallet, lacked the integer-overflow protections later built into the Solidity programming language. Calling it with a specific input value reset a holder’s balance to one, allowing the refund check to pass and releasing the funds.

The recovery was not a unilateral exploit, however. Because the admin function required HongCoin’s multisig to execute, 0xflorent emailed the team, validated the unlock sequence on a test fork of Ethereum’s mainnet, and the team itself signed the unlock transactions.

It signed 41 transactions, one per blocked holder, freeing the roughly 1,000 ETH that was truly stuck. Another seven holders held small enough balances to refund directly without the workaround.

It is the second such recovery 0xflorent has publicized in eight days.

On May 24, he said he had returned 19.329 ETH, worth about $40,590, to its original owners, including 5.141 ETH from a failed January 2018 ICO and 14.190 ETH from seven expired atomic swaps in a Liquality Wallet user account that had become inaccessible after the wallet shut down in 2024.

The recovery lands during a heavy stretch of DeFi exploits, with April alone seeing hundreds of millions of dollars drained across protocols, headlined by a roughly $293 million hit on Kelp DAO.

More For You

Blocky structures linked by rays of light.

The Sui Foundation’s post-mortem published Sunday traces all three outages to interactions between a new address-balance feature shipped in the v1.72 release and the network’s existing gas and consensus logic.

What to know:

  • Sui’s mainnet halted three times on May 28 and 29 after a new v1.72 feature exposed an edge case in the blockchain’s gas-charging logic, according to a post-mortem from the Sui Foundation.
  • The first two outages stemmed from related bugs in how mixed gas payments were handled when transactions lacked…

About the Author

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Stories