Announcement on Hedgey Finance Platform Exploit

BonusBlock vesting contracts for token claims are managed on Hedgey Finance.

A service platform to manage token claims and vestings.

NOTE: The exploit is not related to the BonusBlock project, token smart contracts, or the on-chain marketplace itself. Our audit public report can be checked here: Smart Contract Audits/Audit_Report_BBLK-SCA_PUBLIC_20.pdf

The Hedgey Finance platform had a security exploit today, April 19, 2024, impacting several projects, including BonusBlock. Precise time: 09:28:02 AM +UTC (the overall attack against Hedgey started sooner).

First transaction exploit on Hedgey Finance:

Exploit visualised:

The hacker compromised the vesting schedules of the Hedgey Finance platform and was able to claim tokens by exploiting smart contracts. Successfully in time informed all relevant parties to pause deposits on Bybit and, and managed to remove liquidity on Helix DEX. The hacker was stopped and was unable to sell any tokens on the market, while the liquidity of BonusBlock remained intact.

We extend our gratitude to all the parties involved who helped Hedgey Finance successfully manage this crisis situation.

The next steps are as follows:

  • New token contract, we will be soon updating all parties about this. NOTE: The reason for this change is the exploitation of Hedgey Finance's vesting schedules by the hacker, not a compromise of the token smart contract itself.

  • Await Post Morderm from Hedgey Finance about their exploit

  • A snapshot will be taken before the incident.

  • Vesting contracts will not be redeployed with Hedgey Finance and an alternative secure option is already in place.

  • User tokens are safe, there is no exploit for the token contract. Swaps to the new token will be available prior to relisting on CEX's and DEX.

Thank you, everyone for your support!

