Saturday, June 6, 2026
No Result
View All Result
Bitcoin News Updates
  • Home
  • Bitcoin
  • Crypto Updates
    • Crypto Updates
    • Ethereum
    • Altcoin
    • Crypto Exchanges
  • Blockchain
  • NFT
  • Web3
  • DeFi
  • Metaverse
  • Analysis
  • Regulations
  • Scam Alert
Marketcap
  • Home
  • Bitcoin
  • Crypto Updates
    • Crypto Updates
    • Ethereum
    • Altcoin
    • Crypto Exchanges
  • Blockchain
  • NFT
  • Web3
  • DeFi
  • Metaverse
  • Analysis
  • Regulations
  • Scam Alert
Marketcap
Bitcoin News Updates
No Result
View All Result
Home Ethereum

Failed Ethereum ICO from 2016 simply unlocked 1,003 ETH by exploiting itself

June 2, 2026
in Ethereum
0 0
0
Failed Ethereum ICO from 2016 simply unlocked 1,003 ETH by exploiting itself
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter


A white-hat researcher’s restoration of 1,003.62 ETH from a failed 2016 Ethereum ICO has turned an previous good contract flaw right into a reminder that Ethereum’s earliest technical choices can stay dwell for almost a decade.

The researcher, often known as 0xFlorent, stated he unlocked the ETH from the HongCoin contract after the funds had been trapped for 9 years. Utilizing a June 1 Ethereum value of roughly $1,983, the recovered quantity was value about $1.99 million.

The restoration trusted the unique HongCoin multisig. The HongCoin contract nonetheless required motion from that administration path for the related admin calls.

That made the episode nearer to contract archaeology than to a traditional exploit: the identical immutable code that preserved the refund failure additionally preserved a forgotten route round it.

Someone just drained long-forgotten dormant Ethereum wallets, and the cause may trace back years
Associated Studying

Somebody simply drained long-forgotten dormant Ethereum wallets, and the trigger might hint again years

Tons of of long-inactive Ethereum wallets have been swept right into a tagged deal with whereas researchers and customers nonetheless debate whether or not previous keys, weak pockets tooling, or one other publicity opened the door.

Might 1, 2026 · Liam ‘Akiba’ Wright

HongCoin’s distinction is stark. Ethereum’s base layer stayed nonetheless. A still-valid permission path and coordinated signing from the unique multisig made 48 unique buyers eligible to assert funds by a refund mechanism that had been damaged for years.

How the refund path broke

HongCoin was a 2016 Ethereum undertaking whose public repository described it as a decentralized enterprise fund. The token sale failed to succeed in its funding aim, and contributors have been supposed to have the ability to reclaim their ETH by the contract’s refund perform.

The issue sat contained in the contract’s accounting. Within the HongCoin supply code, the refundMyIcoInvestment() perform checks whether or not the caller’s token steadiness is bigger than tokensCreated. If that situation is true, the refund name fails.

If it passes, the perform zeroes the caller’s token steadiness, clears associated accounting, reduces tokensCreated by that token steadiness, after which sends the refund.

Over time, earlier refunds decreased the worldwide tokensCreated counter. That left bigger holders in a wierd place: they nonetheless had balances tied to their unique claims, however these balances could possibly be too giant for the contract’s remaining counter.

The refund perform then handled them as invalid, blocking the very customers it was presupposed to repay.

The escape path was one other previous piece of code. The multisig-restricted mgmtIssueBountyToken() admin perform may add a equipped quantity to a recipient’s steadiness and to bountyTokensCreated.

That path belonged to the administration facet of the contract, which is why the unique multisig needed to take part. Trendy Solidity arithmetic reverts by default on overflow.

Earlier than Solidity 0.8.0, arithmetic wrapped on overflow until builders added their very own checks. The older habits formed the escape route.

0xFlorent recognized a manner to make use of the admin perform’s arithmetic habits to reset a holder’s steadiness low sufficient for the refund examine to move. The outcome was paradoxical: one stale bug helped undo the sensible harm brought on by one other stale bug.

StageKey detail2016 token saleHongCoin collected ETH for a venture-fund-style Ethereum undertaking that later failed to succeed in its aim.Refund failureThe refund perform rejected bigger holders as soon as the worldwide token counter fell under their balances.Outdated admin pathA multisig-restricted perform nonetheless existed that would change balances utilizing pre-0.8 Solidity arithmetic habits.Whitehat recovery0xFlorent coordinated with the unique HongCoin multisig to make blocked holders eligible to assert funds.On-chain proofA Might 29 transaction reveals a profitable refundMyIcoInvestment() name producing an inner 96 ETH switch.

Flow diagram showing how HongCoin's 2016 failed ICO, refund accounting bug, original multisig, and integer-overflow path unlocked 1,003.62 ETH.Flow diagram showing how HongCoin's 2016 failed ICO, refund accounting bug, original multisig, and integer-overflow path unlocked 1,003.62 ETH.

The multisig made it a coordinated restoration

The multisig requirement set a boundary for the HongCoin restoration. The delicate path required HongCoin’s unique administration deal with to execute the related calls, so the sensible restoration trusted cooperation between the researcher and the previous management path.

The coordination carried as a lot weight because the code. The restoration concerned 41 signed transactions for blocked holders, whereas one other seven smaller holders may refund straight with out the workaround.

The ICO started on Aug. 29, 2016, ended on Oct. 28, 2016, and failed to fulfill its funding aim.

The on-chain file already reveals refund exercise. A Might 29 on-chain transaction known as refundMyIcoInvestment() and produced an inner switch of 96 ETH from the HongCoin contract to an investor deal with.

The highest-level transaction worth was 0 ETH as a result of the precise motion occurred contained in the contract name.

Anybody following the cash ought to separate eligibility from accomplished distribution. The contract state and multisig execution reopened a declare path for funds that had been inaccessible for years.

The seen on-chain examples present refund exercise fairly than a full accounting of each eligible investor’s declare.

The HongCoin case must be learn rigorously earlier than anybody generalizes it to different previous caught funds. The substances have been unusually particular: identifiable contract logic, an admin perform nonetheless usable by the unique management path, a whitehat prepared to coordinate, and sufficient remaining on-chain worth to take the time worthwhile.

The sensible element is possession and permission. The previous perform may change balances, however solely the administration path may name it.

That offers the restoration its moral and operational boundary: exterior analysis discovered the trail, unique signers executed it, and the declare route reopened for buyers.

CryptoSlate Each day Transient

Each day alerts, zero noise.

Market-moving headlines and context delivered each morning in a single tight learn.

5-minute digest 100k+ readers

Free. No spam. Unsubscribe any time.

Whoops, seems to be like there was an issue. Please strive once more.

You’re subscribed. Welcome aboard.

Aave warns $71M exploit recovery could be seized before victims are repaidAave warns $71M exploit recovery could be seized before victims are repaid
Associated Studying

Aave warns $71M exploit restoration could possibly be seized earlier than victims are repaid

The dispute may determine whether or not DeFi restoration funds return to customers first or change into targets for out of doors collectors.

Might 5, 2026 · Gino Matos

The identical info additionally make the case laborious to generalize. Many dormant contracts lack an energetic management key, a clear claimant set, or a public path that makes accountable restoration believable.

That boundary additionally reduces the temptation to deal with the episode as a broad exploit template. The technical mechanism explains why the refund gate reopened, however the story’s consequence comes from the mix of previous code, dwelling permissions, and public settlement.

Related archaeology turns into riskier when a contract lacks a type of components, as a result of discovery can expose a weak point earlier than it creates a usable restoration route.

Ethereum retains the error and the treatment

The broader Ethereum historical past makes the HongCoin restoration greater than a curiosity. A 2025 evaluation citing Coinbase’s Conor Grogan put completely misplaced ETH at greater than 913,111, framed as a conservative estimate throughout consumer and contract-related errors.

That class consists of funds despatched to burn addresses, contract bugs, and main historic incidents.

A few of Ethereum’s most consequential early moments have been additionally restoration debates. In 2016, the DAO laborious fork moved roughly 12 million ETH from DAO-related contracts right into a restoration contract after the community’s defining governance disaster.

In 2017, Parity Applied sciences’ multisig library self-destruct incident blocked 513,774.16 ETH throughout 587 wallets.

These episodes have been bigger and politically heavier than HongCoin. They nonetheless assist body why this smaller restoration resonates.

Timeline matrix showing Ethereum stuck-fund history, including The DAO, Parity, lost ETH estimates, and the 2026 security endowment plan.Timeline matrix showing Ethereum stuck-fund history, including The DAO, Parity, lost ETH estimates, and the 2026 security endowment plan.

Ethereum’s promise that code and state persist is a safety property and a reminiscence system. It preserves errors, half-forgotten assumptions, previous permissions, and the occasional treatment whose future relevance was invisible at deployment.

TheDAO’s leftover rescue money sat for a decade now it’s becoming Ethereum’s permanent $220M security budgetTheDAO’s leftover rescue money sat for a decade now it’s becoming Ethereum’s permanent $220M security budget
Associated Studying

TheDAO’s leftover rescue cash sat for a decade now it’s turning into Ethereum’s everlasting $220M safety funds

Veterans need to stake 69,420 ETH from leftover 2016 restoration funds, producing thousands and thousands yearly for good contract safety.

Jan 30, 2026 · Gino Matos

That lengthy reminiscence now sits beside a maturing safety tradition. In January, Ethereum veterans introduced plans to transform roughly 75,000 ETH in leftover TheDAO restoration funds right into a staked endowment for Ethereum safety.

Comic-style image of an Ethereum treasure chest marked HongCoin ICO, showing explorers recovering 1,003.62 ETH.Comic-style image of an Ethereum treasure chest marked HongCoin ICO, showing explorers recovering 1,003.62 ETH.

The HongCoin case works on a a lot smaller scale, however factors to the identical afterlife of early Ethereum choices.

The subsequent take a look at is recoverability: whether or not different previous contracts comprise paths that can be utilized responsibly. A white-hat restoration wants greater than a bug. It wants a rightful management path, public on-chain proof, cautious disclosure, and a strategy to keep away from turning contract archaeology right into a playbook for opportunistic assaults.

HongCoin reveals that some trapped funds can stay suspended inside previous logic, ready for somebody to grasp each the flaw and the permission construction round it. That may be a hopeful outcome for the 48 buyers now eligible to assert.

It’s also a warning for the remainder of the ecosystem: Ethereum remembers dangerous code, and generally it remembers the escape hatch too.



Source link

Tags: ETHEthereumexploitingFailedICOunlocked
ShareTweetPin
[adinserter block="2"]
Previous Post

Institutional Traders Promote $1,670,000,000 in Bitcoin and Crypto Belongings in Third Straight Week of Outflows: CoinShares

Next Post

Pundit Shares Why Most Individuals Will Miss The XRP Run

Related Posts

Document Retail Shopping for Can’t Push Ethereum Greater – Somebody Greater Is On The Different Facet
Ethereum

Document Retail Shopping for Can’t Push Ethereum Greater – Somebody Greater Is On The Different Facet

June 5, 2026
Bitmine Seeks 0M Elevate To Speed up Ethereum Accumulation Technique
Ethereum

Bitmine Seeks $300M Elevate To Speed up Ethereum Accumulation Technique

June 5, 2026
Ethereum Funding Charges On Binance Jumps To The Highest Degree Of 2026
Ethereum

Ethereum Funding Charges On Binance Jumps To The Highest Degree Of 2026

June 5, 2026
BitMine Copies Saylor’s Playbook With Ethereum Most well-liked Inventory
Ethereum

BitMine Copies Saylor’s Playbook With Ethereum Most well-liked Inventory

June 5, 2026
Ethereum treasury large presents 9.5% payout as BitMine paper losses prime .5 billion
Ethereum

Ethereum treasury large presents 9.5% payout as BitMine paper losses prime $8.5 billion

June 4, 2026
Ethereum Weak spot Might Be Ultimate Part Earlier than Subsequent Market Growth
Ethereum

Ethereum Weak spot Might Be Ultimate Part Earlier than Subsequent Market Growth

June 5, 2026
Next Post
Pundit Shares Why Most Individuals Will Miss The XRP Run

Pundit Shares Why Most Individuals Will Miss The XRP Run

Coinbase Opens India’s T Financial system to Crypto With Direct INR Rails and Futures Buying and selling

Coinbase Opens India’s $4T Financial system to Crypto With Direct INR Rails and Futures Buying and selling

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

World markets by TradingView
Bitcoin News Updates

Navigate crypto volatility with Bitcoin News Updates. Get real-time Bitcoin price alerts, technical analysis, and market snapshots to guide your next trade.

No Result
View All Result

LATEST UPDATES

Argentina’s Probe Into Libra Token Frozen Over Lack of Tech Instruments

Hyperliquid Faces 5 Paths As US Regulatory Strain Builds

Remembering Julio Le Parc, a pioneer of kinetic artwork – The Artwork Newspaper

POPULAR

SoFi Simply Launched a Financial institution-Backed Stablecoin

Coinbase Opens India’s $4T Financial system to Crypto With Direct INR Rails and Futures Buying and selling

Establishments Are Loading Up On XRP, However Liquidity Tells A Completely different Story

  • About us
  • Advertise with us
  • Disclaimer 
  • Privacy Policy
  • DMCA 
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact Us

Copyright © 2026 Bitcoin News Updates.
Bitcoin News Updates is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin(BTC)$60,106.00-4.78%
  • tetherTether(USDT)$1.000.08%
  • ethereumEthereum(ETH)$1,543.25-10.96%
  • binancecoinBNB(BNB)$566.19-5.17%
  • usd-coinUSDC(USDC)$1.000.02%
  • rippleXRP(XRP)$1.07-6.16%
  • solanaSolana(SOL)$61.43-8.53%
  • tronTRON(TRX)$0.319556-2.56%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.95%
  • HyperliquidHyperliquid(HYPE)$57.97-7.46%
No Result
View All Result
  • Home
  • Bitcoin
  • Crypto Updates
    • Crypto Updates
    • Ethereum
    • Altcoin
    • Crypto Exchanges
  • Blockchain
  • NFT
  • Web3
  • DeFi
  • Metaverse
  • Analysis
  • Regulations
  • Scam Alert

Copyright © 2026 Bitcoin News Updates.
Bitcoin News Updates is not responsible for the content of external sites.