By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Notification
yourcryptonewstoday yourcryptonewstoday
  • Home
  • News
    • Crypto Bubbles
    • Regulations
    • Metaverse
  • MarketCap
  • Altcoins
    • Solana
  • Crypto
    • Bitcoin
    • Ethereum
    • Cardano
  • Blockchain
  • Market
    • Nft
  • Mining
  • Exchange
  • Analysis
    • Evaluation
    • Multi Currency
Reading: Failed Ethereum ICO from 2016 just unlocked 1,003 ETH by exploiting itself
Share
bitcoin
Bitcoin (BTC) $ 71,426.00
ethereum
Ethereum (ETH) $ 1,991.31
tether
Tether (USDT) $ 0.998704
bnb
BNB (BNB) $ 690.32
usd-coin
USDC (USDC) $ 0.999634
xrp
XRP (XRP) $ 1.30
binance-usd
BUSD (BUSD) $ 0.998304
dogecoin
Dogecoin (DOGE) $ 0.099873
cardano
Cardano (ADA) $ 0.230444
solana
Solana (SOL) $ 80.80
polkadot
Polkadot (DOT) $ 1.16
tron
TRON (TRX) $ 0.344291
Your Crypto News TodayYour Crypto News Today
  • Home
  • News
  • MarketCap
  • Altcoins
  • Crypto
  • Blockchain
  • Market
  • Mining
  • Exchange
  • Analysis
Search
  • Home
  • News
    • Crypto Bubbles
    • Regulations
    • Metaverse
  • MarketCap
  • Altcoins
    • Solana
  • Crypto
    • Bitcoin
    • Ethereum
    • Cardano
  • Blockchain
  • Market
    • Nft
  • Mining
  • Exchange
  • Analysis
    • Evaluation
    • Multi Currency
© 2024 All Rights reserved | Protected by Your Cryptonews Today
Your Crypto News Today > News > Crypto > Ethereum > Failed Ethereum ICO from 2016 just unlocked 1,003 ETH by exploiting itself
Ethereum

Failed Ethereum ICO from 2016 just unlocked 1,003 ETH by exploiting itself

June 1, 2026 11 Min Read
Share
Liam 'Akiba' Wright

Table of Contents

Toggle
    • Somebody simply drained long-forgotten dormant Ethereum wallets, and the trigger might hint again years
  • How the refund path broke
  • The multisig made it a coordinated restoration
    • Each day indicators, zero noise.
    • Aave warns $71M exploit restoration might be seized earlier than victims are repaid
  • Ethereum retains the error and the treatment
    • TheDAO’s leftover rescue cash sat for a decade now it’s turning into Ethereum’s everlasting $220M safety price range

A white-hat researcher’s restoration of 1,003.62 ETH from a failed 2016 Ethereum ICO has turned an outdated sensible contract flaw right into a reminder that Ethereum’s earliest technical choices can stay reside for practically a decade.

The researcher, generally known as 0xFlorent, stated he unlocked the ETH from the HongCoin contract after the funds had been trapped for 9 years. Utilizing a June 1 Ethereum worth of roughly $1,983, the recovered quantity was price about $1.99 million.

The restoration trusted the unique HongCoin multisig. The HongCoin contract nonetheless required motion from that administration path for the related admin calls.

That made the episode nearer to contract archaeology than to a standard exploit: the identical immutable code that preserved the refund failure additionally preserved a forgotten route round it.

Associated Studying

Somebody simply drained long-forgotten dormant Ethereum wallets, and the trigger might hint again years

Tons of of long-inactive Ethereum wallets have been swept right into a tagged handle whereas researchers and customers nonetheless debate whether or not outdated keys, weak pockets tooling, or one other publicity opened the door.

Might 1, 2026 · Liam ‘Akiba’ Wright

HongCoin’s distinction is stark. Ethereum’s base layer stayed nonetheless. A still-valid permission path and coordinated signing from the unique multisig made 48 authentic buyers eligible to assert funds by means of a refund mechanism that had been damaged for years.

How the refund path broke

HongCoin was a 2016 Ethereum undertaking whose public repository described it as a decentralized enterprise fund. The token sale failed to succeed in its funding aim, and contributors have been supposed to have the ability to reclaim their ETH by means of the contract’s refund perform.

The issue sat contained in the contract’s accounting. Within the HongCoin supply code, the refundMyIcoInvestment() perform checks whether or not the caller’s token steadiness is bigger than tokensCreated. If that situation is true, the refund name fails.

If it passes, the perform zeroes the caller’s token steadiness, clears associated accounting, reduces tokensCreated by that token steadiness, after which sends the refund.

Over time, earlier refunds lowered the worldwide tokensCreated counter. That left bigger holders in an odd place: they nonetheless had balances tied to their authentic claims, however these balances might be too giant for the contract’s remaining counter.

The refund perform then handled them as invalid, blocking the very customers it was purported to repay.

The escape path was one other outdated piece of code. The multisig-restricted mgmtIssueBountyToken() admin perform may add a provided quantity to a recipient’s steadiness and to bountyTokensCreated.

That path belonged to the administration aspect of the contract, which is why the unique multisig needed to take part. Trendy Solidity arithmetic reverts by default on overflow.

Earlier than Solidity 0.8.0, arithmetic wrapped on overflow except builders added their very own checks. The older habits formed the escape route.

0xFlorent recognized a approach to make use of the admin perform’s arithmetic habits to reset a holder’s steadiness low sufficient for the refund examine to cross. The consequence was paradoxical: one stale bug helped undo the sensible harm brought on by one other stale bug.

StageKey element
2016 token saleHongCoin collected ETH for a venture-fund-style Ethereum undertaking that later failed to succeed in its aim.
Refund failureThe refund perform rejected bigger holders as soon as the worldwide token counter fell beneath their balances.
Previous admin pathA multisig-restricted perform nonetheless existed that might change balances utilizing pre-0.8 Solidity arithmetic habits.
Whitehat restoration0xFlorent coordinated with the unique HongCoin multisig to make blocked holders eligible to assert funds.
On-chain proofA Might 29 transaction reveals a profitable refundMyIcoInvestment() name producing an inner 96 ETH switch.

The multisig made it a coordinated restoration

The multisig requirement set a boundary for the HongCoin restoration. The delicate path required HongCoin’s authentic administration handle to execute the related calls, so the sensible restoration trusted cooperation between the researcher and the outdated management path.

The coordination carried as a lot weight because the code. The restoration concerned 41 signed transactions for blocked holders, whereas one other seven smaller holders may refund instantly with out the workaround.

The ICO started on Aug. 29, 2016, ended on Oct. 28, 2016, and failed to satisfy its funding aim.

The on-chain report already reveals refund exercise. A Might 29 on-chain transaction known as refundMyIcoInvestment() and produced an inner switch of 96 ETH from the HongCoin contract to an investor handle.

The highest-level transaction worth was 0 ETH as a result of the precise motion occurred contained in the contract name.

Anybody following the cash ought to separate eligibility from accomplished distribution. The contract state and multisig execution reopened a declare path for funds that had been inaccessible for years.

The seen on-chain examples present refund exercise slightly than a full accounting of each eligible investor’s declare.

The HongCoin case must be learn rigorously earlier than anybody generalizes it to different outdated caught funds. The substances have been unusually particular: identifiable contract logic, an admin perform nonetheless usable by the unique management path, a whitehat keen to coordinate, and sufficient remaining on-chain worth to take the time worthwhile.

The sensible element is possession and permission. The outdated perform may change balances, however solely the administration path may name it.

That provides the restoration its moral and operational boundary: exterior analysis discovered the trail, authentic signers executed it, and the declare route reopened for buyers.

yourcryptonewstoday Each day Temporary

Each day indicators, zero noise.

Market-moving headlines and context delivered each morning in a single tight learn.

5-minute digest 100k+ readers

Free. No spam. Unsubscribe any time.

Whoops, appears to be like like there was an issue. Please strive once more.

You’re subscribed. Welcome aboard.

Associated Studying

Aave warns $71M exploit restoration might be seized earlier than victims are repaid

The dispute may resolve whether or not DeFi restoration funds return to customers first or change into targets for out of doors collectors.

Might 5, 2026 · Gino Matos

The identical information additionally make the case arduous to generalize. Many dormant contracts lack an energetic management key, a clear claimant set, or a public path that makes accountable restoration believable.

That boundary additionally reduces the temptation to deal with the episode as a broad exploit template. The technical mechanism explains why the refund gate reopened, however the story’s consequence comes from the mix of outdated code, dwelling permissions, and public settlement.

Comparable archaeology turns into riskier when a contract lacks a kind of parts, as a result of discovery can expose a weak spot earlier than it creates a usable restoration route.

Ethereum retains the error and the treatment

The broader Ethereum historical past makes the HongCoin restoration greater than a curiosity. A 2025 evaluation citing Coinbase’s Conor Grogan put completely misplaced ETH at greater than 913,111, framed as a conservative estimate throughout consumer and contract-related errors.

That class contains funds despatched to burn addresses, contract bugs, and main historic incidents.

A few of Ethereum’s most consequential early moments have been additionally restoration debates. In 2016, the DAO arduous fork moved roughly 12 million ETH from DAO-related contracts right into a restoration contract after the community’s defining governance disaster.

In 2017, Parity Applied sciences’ multisig library self-destruct incident blocked 513,774.16 ETH throughout 587 wallets.

These episodes have been bigger and politically heavier than HongCoin. They nonetheless assist body why this smaller restoration resonates.

Ethereum’s promise that code and state persist is a safety property and a reminiscence system. It preserves errors, half-forgotten assumptions, outdated permissions, and the occasional treatment whose future relevance was invisible at deployment.

Associated Studying

TheDAO’s leftover rescue cash sat for a decade now it’s turning into Ethereum’s everlasting $220M safety price range

Veterans wish to stake 69,420 ETH from leftover 2016 restoration funds, producing thousands and thousands yearly for sensible contract safety.

Jan 30, 2026 · Gino Matos

That lengthy reminiscence now sits beside a maturing safety tradition. In January, Ethereum veterans introduced plans to transform roughly 75,000 ETH in leftover TheDAO restoration funds right into a staked endowment for Ethereum safety.

The HongCoin case works on a a lot smaller scale, however factors to the identical afterlife of early Ethereum choices.

The subsequent check is recoverability: whether or not different outdated contracts include paths that can be utilized responsibly. A white-hat restoration wants greater than a bug. It wants a rightful management path, public on-chain proof, cautious disclosure, and a solution to keep away from turning contract archaeology right into a playbook for opportunistic assaults.

HongCoin reveals that some trapped funds can stay suspended inside outdated logic, ready for somebody to grasp each the flaw and the permission construction round it. That could be a hopeful consequence for the 48 buyers now eligible to assert.

It’s also a warning for the remainder of the ecosystem: Ethereum remembers unhealthy code, and generally it remembers the escape hatch too.

You Might Also Like

XRP defiant amid Bitcoin collapse as a massive institutional migration quietly shifts billions into Ripple

Bitcoin Price Could See Another Crash, But What Is The Long-Term Prognosis?

The Bulls Are in Control of Ethereum: What Will Happen Next?

$105,000 ETH Long Enters Profit as Ethereum Returns to $2,000

BitMine becomes the first company to surpass 1M ETH holdings worth over $5B

TAGGED:AnalysisCoinsCommunityCryptoDAOsEthereumEthereum AnalysisEthereum NewsFeaturedInvestmentsWallets
Share This Article
Facebook Twitter Copy Link
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News

The developer who broke Lightning launches Cube, non-custodial Bitcoin contracts
The developer who broke Lightning launches Cube, non-custodial Bitcoin contracts
AvaCloud Ushers in New Era of Blockchain Privacy with Acquisition of EtraPay and Launch of Privacy Suite
AvaCloud Ushers in New Era of Blockchain Privacy with Acquisition of EtraPay and Launch of Privacy Suite
TRON's Justin Sun Debunks Binance Listing Rumors
TRON’s Justin Sun Debunks Binance Listing Rumors
Universal Health Token Debuts ‘PILLARS OF HEALTH’ NFT Collection
Universal Health Token Debuts ‘PILLARS OF HEALTH’ NFT Collection
Paragon Launches Flagship Loot-Box NFTs, Sell Out in Seconds
Paragon Launches Flagship Loot-Box NFTs, Sell Out in Seconds
Are NFTs Making a Return to Auction Houses?
Are NFTs Making a Return to Auction Houses?

You Might Also Like

Bitcoin
Bitcoin

Bitcoin Set To Hit $350,000 Despite BlackRock Sell-Off Fears, Robert Kiyosaki Says

December 28, 2024
Thanksgiving
Bitcoin

Michael Saylor’s Thanksgiving: A Crypto Feast Featuring Bitcoin-Topped Turkey

December 8, 2024
image
Ethereum

Failure at $2.4K Spells More Trouble Ahead for ETH

May 12, 2026
image
Ethereum

Ethereum Just Broke $2,100! Is This the Start of the REAL Altseason Explosion

February 8, 2026
yourcryptonewstoday yourcryptonewstoday
yourcryptonewstoday yourcryptonewstoday

"In the fast-paced world of digital finance, staying informed is essential, and we’re here to help you navigate the evolving landscape of crypto currencies, blockchain, & digital assets."

Editor Choice

Nearly $3 Billion in Bitcoin and Ethereum Options Expire Today Amid Mixed Market Sentiment
“The question is not if bitcoin will rise again, but when”
Dogecoin experiments with post-quantum signatures without altering its current protocol

Subscribe

* indicates required
/* real people should not fill this in and expect good things - do not remove this or risk form bot signups */

Intuit Mailchimp

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Linkedin Facebook
  • About Us
  • Contact Us
  • Disclaimer
  • Terms of Service
  • Privacy Policy
Reading: Failed Ethereum ICO from 2016 just unlocked 1,003 ETH by exploiting itself
Share
Follow US
© 2025 All Rights reserved | Protected by Your Crypto News Today
Welcome Back!

Sign in to your account

Lost your password?