A white hat hacker has found a solution to free funds trapped for almost 10 years in a faulty contract.
The following is a summary of the information that you will find on this page.
- White hat hackers helped to recover 1,003 ETH, worth around $2 million, from a Hong Coin ICO that failed in 2016.
- After a software bug stopped investors receiving refunds automatically, the money remained frozen for more than ten years.
- The hacker was able to recover the funds after he identified an integer-overflow bug and collaborated with the creators of the project in order to unlock the refund system.
A Sunday post by white hat hacker 0xflorent under the pseudonym ‘0xflorent’ revealed that the recovered ETH was the property of 48 investors. The Hong Coin token sale (HONG), a venture capital decentralized project, never got off the ground after it failed to reach its funding target.
According to 0xflorent’s explanation, the ICO was intended to return investors’ ETH automatically if funding goals were not met. An error in the refund feature prevented the process from functioning, leaving funds locked permanently despite the failure of the sale.
Etherscan blockchain records indicate that refunds of ETH have begun. The blockchain records from Etherscan show that refunds have already begun.
Hong Coin, a decentralized organization that focuses on venture capital investments was launched in 2016. In a promotional video, published in 2016, a voting structure was described whereby token holders could vote for projects to receive funding through the pool managed by the community.
The ICO was launched on August 29th, 2016 and closed on October 28th 2016. Participants were to be rewarded with 250,000,000 HONG tokens over several funding phases if they contributed ETH. Investors became eligible to receive refunds because the project failed to reach its funding target.
Recovery path from integer overflow bug
Detailing the recovery, 0xflorent stated that the solution came from an administrative function overlooked which had an integer overflow.
The white hat claimed that invoking a function using a certain input would reset the balance of a token owner and allow the refund conditions within the contract to be executed correctly. 0xflorent, working with the HONG original creators demonstrated that the flaw can be exploited to free the trapped ETH funds without moving the funds out of the contract.
“The way out was an admin function with an integer overflow vulnerability,” 0xflorent has written on X. “Calling it with a specific input resets a holder’s balance and unblocks the refund check.”
It is one of many cases in which white hat hackers intervened after discovering vulnerabilities to return or recover cryptocurrency funds. smart contracts Infrastructure for protocol and data exchange.
Blockaid, a blockchain security company, announced its launch in early May. reported A white-hat hacker exploited an Arbitrum dark pool on Renegade.fi, draining temporarily about $209,000 and then returning over 90% of assets.
Blockaid says the error was due to deployment and migrating errors, which led to unauthorized modifications of smart contracts connected to V1’s dark pool.
Renegade’s exploiter, in messages posted on the chain following the incident, argued that disclosing the vulnerability was the best way to secure user funds. They also pointed out that it is a simple issue and that other malicious attackers may have had the ability to do far more damage.
Separately, 0xflorent disclosed They announced on 24 May that they recovered a total 19.33 ETH worth approximately $46,600 from a January 2018 ICO failed project, and from a Liquality Wallet holder whose funds were trapped by a cross chain transfer protocol.
“This article is not financial advice.”
“Always do your own research before making any type of investment.”
“ItsDailyCrypto is not responsible for any activities you perform outside ItsDailyCrypto.”
Source: crypto.news

