No Result
View All Result
  • Login
Monday, June 1, 2026
FeeOnlyNews.com
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
No Result
View All Result
FeeOnlyNews.com
No Result
View All Result
Home Cryptocurrency

Failed Ethereum ICO from 2016 just unlocked 1,003 ETH by exploiting itself

by FeeOnlyNews.com
1 hour ago
in Cryptocurrency
Reading Time: 8 mins read
A A
0
Failed Ethereum ICO from 2016 just unlocked 1,003 ETH by exploiting itself
Share on FacebookShare on TwitterShare on LInkedIn


A white-hat researcher’s recovery of 1,003.62 ETH from a failed 2016 Ethereum ICO has turned an old smart contract flaw into a reminder that Ethereum’s earliest technical decisions can remain live for nearly a decade.

The researcher, known as 0xFlorent, said he unlocked the ETH from the HongCoin contract after the funds had been trapped for nine years. Using a June 1 Ethereum price of roughly $1,983, the recovered amount was worth about $1.99 million.

The recovery depended on the original HongCoin multisig. The HongCoin contract still required action from that management path for the relevant admin calls.

That made the episode closer to contract archaeology than to a conventional exploit: the same immutable code that preserved the refund failure also preserved a forgotten route around it.

Someone just drained long-forgotten dormant Ethereum wallets, and the cause may trace back years
Related Reading

Someone just drained long-forgotten dormant Ethereum wallets, and the cause may trace back years

Hundreds of long-inactive Ethereum wallets were swept into a tagged address while researchers and users still debate whether old keys, weak wallet tooling, or another exposure opened the door.

May 1, 2026 · Liam ‘Akiba’ Wright

HongCoin’s contrast is stark. Ethereum’s base layer stayed still. A still-valid permission path and coordinated signing from the original multisig made 48 original investors eligible to claim funds through a refund mechanism that had been broken for years.

How the refund path broke

HongCoin was a 2016 Ethereum project whose public repository described it as a decentralized venture fund. The token sale failed to reach its funding goal, and contributors were supposed to be able to reclaim their ETH through the contract’s refund function.

The problem sat inside the contract’s accounting. In the HongCoin source code, the refundMyIcoInvestment() function checks whether the caller’s token balance is greater than tokensCreated. If that condition is true, the refund call fails.

If it passes, the function zeroes the caller’s token balance, clears related accounting, reduces tokensCreated by that token balance, and then sends the refund.

Over time, earlier refunds reduced the global tokensCreated counter. That left larger holders in a strange position: they still had balances tied to their original claims, but those balances could be too large for the contract’s remaining counter.

The refund function then treated them as invalid, blocking the very users it was supposed to repay.

The escape path was another old piece of code. The multisig-restricted mgmtIssueBountyToken() admin function could add a supplied amount to a recipient’s balance and to bountyTokensCreated.

That path belonged to the management side of the contract, which is why the original multisig had to participate. Modern Solidity arithmetic reverts by default on overflow.

Before Solidity 0.8.0, arithmetic wrapped on overflow unless developers added their own checks. The older behavior shaped the escape route.

0xFlorent identified a way to use the admin function’s arithmetic behavior to reset a holder’s balance low enough for the refund check to pass. The result was paradoxical: one stale bug helped undo the practical damage caused by another stale bug.

StageKey detail2016 token saleHongCoin collected ETH for a venture-fund-style Ethereum project that later failed to reach its goal.Refund failureThe refund function rejected larger holders once the global token counter fell below their balances.Old admin pathA multisig-restricted function still existed that could change balances using pre-0.8 Solidity arithmetic behavior.Whitehat recovery0xFlorent coordinated with the original HongCoin multisig to make blocked holders eligible to claim funds.On-chain proofA May 29 transaction shows a successful refundMyIcoInvestment() call producing an internal 96 ETH transfer.

Flow diagram showing how HongCoin's 2016 failed ICO, refund accounting bug, original multisig, and integer-overflow path unlocked 1,003.62 ETH.Flow diagram showing how HongCoin's 2016 failed ICO, refund accounting bug, original multisig, and integer-overflow path unlocked 1,003.62 ETH.

The multisig made it a coordinated recovery

The multisig requirement set a boundary for the HongCoin recovery. The sensitive path required HongCoin’s original management address to execute the relevant calls, so the practical recovery depended on cooperation between the researcher and the old control path.

The coordination carried as much weight as the code. The recovery involved 41 signed transactions for blocked holders, while another seven smaller holders could refund directly without the workaround.

The ICO began on Aug. 29, 2016, ended on Oct. 28, 2016, and failed to meet its funding goal.

The on-chain record already shows refund activity. A May 29 on-chain transaction called refundMyIcoInvestment() and produced an internal transfer of 96 ETH from the HongCoin contract to an investor address.

The top-level transaction value was 0 ETH because the actual movement happened inside the contract call.

Anyone following the money should separate eligibility from completed distribution. The contract state and multisig execution reopened a claim path for funds that had been inaccessible for years.

The visible on-chain examples show refund activity rather than a full accounting of every eligible investor’s claim.

The HongCoin case should be read carefully before anyone generalizes it to other old stuck funds. The ingredients were unusually specific: identifiable contract logic, an admin function still usable by the original control path, a whitehat willing to coordinate, and enough remaining on-chain value to make the effort worthwhile.

The practical detail is ownership and permission. The old function could change balances, but only the management path could call it.

That gives the recovery its ethical and operational boundary: outside research found the path, original signers executed it, and the claim route reopened for investors.

CryptoSlate Daily Brief

Daily signals, zero noise.

Market-moving headlines and context delivered every morning in one tight read.

5-minute digest 100k+ readers

Free. No spam. Unsubscribe any time.

Whoops, looks like there was a problem. Please try again.

You’re subscribed. Welcome aboard.

Aave warns $71M exploit recovery could be seized before victims are repaidAave warns $71M exploit recovery could be seized before victims are repaid
Related Reading

Aave warns $71M exploit recovery could be seized before victims are repaid

The dispute could decide whether DeFi recovery funds go back to users first or become targets for outside creditors.

May 5, 2026 · Gino Matos

The same facts also make the case hard to generalize. Many dormant contracts lack an active control key, a clean claimant set, or a public trail that makes responsible recovery plausible.

That boundary also reduces the temptation to treat the episode as a broad exploit template. The technical mechanism explains why the refund gate reopened, but the story’s consequence comes from the combination of old code, living permissions, and public settlement.

Similar archaeology becomes riskier when a contract lacks one of those elements, because discovery can expose a weakness before it creates a usable recovery route.

Ethereum keeps the mistake and the remedy

The broader Ethereum history makes the HongCoin recovery more than a curiosity. A 2025 analysis citing Coinbase’s Conor Grogan put permanently lost ETH at more than 913,111, framed as a conservative estimate across user and contract-related errors.

That category includes funds sent to burn addresses, contract bugs, and major historical incidents.

Some of Ethereum’s most consequential early moments were also recovery debates. In 2016, the DAO hard fork moved roughly 12 million ETH from DAO-related contracts into a recovery contract after the network’s defining governance crisis.

In 2017, Parity Technologies’ multisig library self-destruct incident blocked 513,774.16 ETH across 587 wallets.

Those episodes were larger and politically heavier than HongCoin. They still help frame why this smaller recovery resonates.

Timeline matrix showing Ethereum stuck-fund history, including The DAO, Parity, lost ETH estimates, and the 2026 security endowment plan.Timeline matrix showing Ethereum stuck-fund history, including The DAO, Parity, lost ETH estimates, and the 2026 security endowment plan.

Ethereum’s promise that code and state persist is a security property and a memory system. It preserves errors, half-forgotten assumptions, old permissions, and the occasional remedy whose future relevance was invisible at deployment.

TheDAO’s leftover rescue money sat for a decade now it’s becoming Ethereum’s permanent $220M security budgetTheDAO’s leftover rescue money sat for a decade now it’s becoming Ethereum’s permanent $220M security budget
Related Reading

TheDAO’s leftover rescue money sat for a decade now it’s becoming Ethereum’s permanent $220M security budget

Veterans want to stake 69,420 ETH from leftover 2016 recovery funds, generating millions yearly for smart contract security.

Jan 30, 2026 · Gino Matos

That long memory now sits beside a maturing security culture. In January, Ethereum veterans announced plans to convert roughly 75,000 ETH in leftover TheDAO recovery funds into a staked endowment for Ethereum security.

Comic-style image of an Ethereum treasure chest marked HongCoin ICO, showing explorers recovering 1,003.62 ETH.Comic-style image of an Ethereum treasure chest marked HongCoin ICO, showing explorers recovering 1,003.62 ETH.

The HongCoin case works on a much smaller scale, but points to the same afterlife of early Ethereum decisions.

The next test is recoverability: whether other old contracts contain paths that can be used responsibly. A white-hat recovery needs more than a bug. It needs a rightful control path, public on-chain evidence, careful disclosure, and a way to avoid turning contract archaeology into a playbook for opportunistic attacks.

HongCoin shows that some trapped funds can remain suspended inside old logic, waiting for someone to understand both the flaw and the permission structure around it. That is a hopeful result for the 48 investors now eligible to claim.

It is also a warning for the rest of the ecosystem: Ethereum remembers bad code, and sometimes it remembers the escape hatch too.



Source link

Tags: ETHEthereumExploitingFailedICOUnlocked
ShareTweetShare
Previous Post

June Mortgage Outlook: Rates Could Climb as Hopes Fade for a Fed Cut

Next Post

Here’s What Put Seaport Entertainment Group (SEG) on a Strong Footing For Success

Related Posts

Binance Adds 7,000 U.S. Stocks as Crypto Exchanges Race to Become Multi-Asset Brokers

Binance Adds 7,000 U.S. Stocks as Crypto Exchanges Race to Become Multi-Asset Brokers

by FeeOnlyNews.com
June 1, 2026
0

LMAX Digital: Crypto Market Outlook - Regulation, Tokenization & Institutional Adoption LMAX Digital: Crypto Market Outlook - Regulation, Tokenization &...

XRP To ,000? Expert Lays Out Macro Domino Theory

XRP To $1,000? Expert Lays Out Macro Domino Theory

by FeeOnlyNews.com
June 1, 2026
0

Jake Claver has outlined his macro thesis for why XRP could eventually reach $1,000, arguing in a May 31 interview...

Powell Warns the Federal Reserve Won’t Survive if a President Can Fire Officials Over Policy

Powell Warns the Federal Reserve Won’t Survive if a President Can Fire Officials Over Policy

by FeeOnlyNews.com
June 1, 2026
0

Key TakeawaysPowell said the Federal Reserve forfeits public trust if a president can dismiss officials over policy, per June 1...

White Hat Helps Recover  Million from 2016 ICO Project

White Hat Helps Recover $2 Million from 2016 ICO Project

by FeeOnlyNews.com
May 31, 2026
0

A pseudonymous white hat hacker has helped recover $2 million worth of Ether locked in a faulty initial coin offering...

Circle Targets Post-Quantum Security In Bold USDC Roadmap

Circle Targets Post-Quantum Security In Bold USDC Roadmap

by FeeOnlyNews.com
May 31, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Users who fail to migrate their accounts...

Crypto Market This Week: US Jobs Data, Global Inflation, CLARITY Act In Focus

Crypto Market This Week: US Jobs Data, Global Inflation, CLARITY Act In Focus

by FeeOnlyNews.com
May 31, 2026
0

This week, the crypto market awaits a slew of U.S. economic data, a Fed statement and inflation reports from key...

Next Post
Here’s What Put Seaport Entertainment Group (SEG) on a Strong Footing For Success

Here’s What Put Seaport Entertainment Group (SEG) on a Strong Footing For Success

  • Trending
  • Comments
  • Latest
10 States Offering Free or Low‑Cost College Courses for Residents Over 60

10 States Offering Free or Low‑Cost College Courses for Residents Over 60

May 13, 2026
The New Medicare Coding Change Confusing Pharmacies Across Multiple States

The New Medicare Coding Change Confusing Pharmacies Across Multiple States

May 11, 2026
Epstein Class All-In on Massie Primary But Do Midterms Matter?

Epstein Class All-In on Massie Primary But Do Midterms Matter?

May 13, 2026
Memorial Day 2026: Take Advantage of Food Freebies, Deals

Memorial Day 2026: Take Advantage of Food Freebies, Deals

May 23, 2026
Latam Insights: Coinbase Co-Founder Eyes Venezuela as Grupo Salinas Embraces Stablecoins

Latam Insights: Coinbase Co-Founder Eyes Venezuela as Grupo Salinas Embraces Stablecoins

May 17, 2026
The 18 Largest US Funding Rounds of April 2026 – AlleyWatch

The 18 Largest US Funding Rounds of April 2026 – AlleyWatch

May 15, 2026
Failed Ethereum ICO from 2016 just unlocked 1,003 ETH by exploiting itself

Failed Ethereum ICO from 2016 just unlocked 1,003 ETH by exploiting itself

0
8 Reasons Generation Jones Is Reclaiming Its Identity From Traditional Senior Labels

8 Reasons Generation Jones Is Reclaiming Its Identity From Traditional Senior Labels

0
Here’s What Put Seaport Entertainment Group (SEG) on a Strong Footing For Success

Here’s What Put Seaport Entertainment Group (SEG) on a Strong Footing For Success

0
Making Your 80,000 Hours Count (with Benjamin Todd)

Making Your 80,000 Hours Count (with Benjamin Todd)

0
Explained: NSE extends F&O trading by 10 minutes. What changes for traders?

Explained: NSE extends F&O trading by 10 minutes. What changes for traders?

0
He Was Laid Off From TSA, Now He Owns an Entire Rental Portfolio

He Was Laid Off From TSA, Now He Owns an Entire Rental Portfolio

0
Here’s What Put Seaport Entertainment Group (SEG) on a Strong Footing For Success

Here’s What Put Seaport Entertainment Group (SEG) on a Strong Footing For Success

June 1, 2026
Failed Ethereum ICO from 2016 just unlocked 1,003 ETH by exploiting itself

Failed Ethereum ICO from 2016 just unlocked 1,003 ETH by exploiting itself

June 1, 2026
June Mortgage Outlook: Rates Could Climb as Hopes Fade for a Fed Cut

June Mortgage Outlook: Rates Could Climb as Hopes Fade for a Fed Cut

June 1, 2026
The elderly and injured are using robots as home care support to help them get around their home

The elderly and injured are using robots as home care support to help them get around their home

June 1, 2026
Remembering the Mogambo Guru | Mises Institute

Remembering the Mogambo Guru | Mises Institute

June 1, 2026
Motorola Solutions buys Israeli co D-Fend for .5b

Motorola Solutions buys Israeli co D-Fend for $1.5b

June 1, 2026
FeeOnlyNews.com

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Economy
  • Financial Planning
  • Investing
  • Market Analysis
  • Markets
  • Money
  • Personal Finance
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Here’s What Put Seaport Entertainment Group (SEG) on a Strong Footing For Success
  • Failed Ethereum ICO from 2016 just unlocked 1,003 ETH by exploiting itself
  • June Mortgage Outlook: Rates Could Climb as Hopes Fade for a Fed Cut
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclaimers
  • About Us
  • Contact Us

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.