Cryptocurrency
Failed Ethereum ICO from 2016 just unlocked 1,003 ETH by exploiting itself – Crypto News
A white-hat researcher’s recovery of 1,003.62 ETH from a failed 2016 Ethereum ICO has turned an old smart contract flaw into a reminder that Ethereum’s earliest technical decisions can remain live for nearly a decade.
The researcher, known as 0xFlorent, said he unlocked the ETH from the HongCoin contract after the funds had been trapped for nine years. Using a June 1 Ethereum price of roughly $1,983, the recovered amount was worth about $1.99 million.
The recovery depended on the original HongCoin multisig. The HongCoin contract still required action from that management path for the relevant admin calls.
That made the episode closer to contract archaeology than to a conventional exploit: the same immutable code that preserved the refund failure also preserved a forgotten route around it.
HongCoin’s contrast is stark. Ethereum’s base layer stayed still. A still-valid permission path and coordinated signing from the original multisig made 48 original investors eligible to claim funds through a refund mechanism that had been broken for years.
How the refund path broke
HongCoin was a 2016 Ethereum project whose public repository described it as a decentralized venture fund. The token sale failed to reach its funding goal, and contributors were supposed to be able to reclaim their ETH through the contract’s refund function.
The problem sat inside the contract’s accounting. In the HongCoin source code, the refundMyIcoInvestment() function checks whether the caller’s token balance is greater than tokensCreated. If that condition is true, the refund call fails.
If it passes, the function zeroes the caller’s token balance, clears related accounting, reduces tokensCreated by that token balance, and then sends the refund.
Over time, earlier refunds reduced the global tokensCreated counter. That left larger holders in a strange position: they still had balances tied to their original claims, but those balances could be too large for the contract’s remaining counter.
The refund function then treated them as invalid, blocking the very users it was supposed to repay.
The escape path was another old piece of code. The multisig-restricted mgmtIssueBountyToken() admin function could add a supplied amount to a recipient’s balance and to bountyTokensCreated.
That path belonged to the management side of the contract, which is why the original multisig had to participate. Modern Solidity arithmetic reverts by default on overflow.
Before Solidity 0.8.0, arithmetic wrapped on overflow unless developers added their own checks. The older behavior shaped the escape route.
0xFlorent identified a way to use the admin function’s arithmetic behavior to reset a holder’s balance low enough for the refund check to pass. The result was paradoxical: one stale bug helped undo the practical damage caused by another stale bug.
| Stage | Key detail |
|---|---|
| 2016 token sale | HongCoin collected ETH for a venture-fund-style Ethereum project that later failed to reach its goal. |
| Refund failure | The refund function rejected larger holders once the global token counter fell below their balances. |
| Old admin path | A multisig-restricted function still existed that could change balances using pre-0.8 Solidity arithmetic behavior. |
| Whitehat recovery | 0xFlorent coordinated with the original HongCoin multisig to make blocked holders eligible to claim funds. |
| On-chain proof | A May 29 transaction shows a successful refundMyIcoInvestment() call producing an internal 96 ETH transfer. |
The multisig made it a coordinated recovery
The multisig requirement set a boundary for the HongCoin recovery. The sensitive path required HongCoin’s original management address to execute the relevant calls, so the practical recovery depended on cooperation between the researcher and the old control path.
The coordination carried as much weight as the code. The recovery involved 41 signed transactions for blocked holders, while another seven smaller holders could refund directly without the workaround.
The ICO began on Aug. 29, 2016, ended on Oct. 28, 2016, and failed to meet its funding goal.
The on-chain record already shows refund activity. A May 29 on-chain transaction called refundMyIcoInvestment() and produced an internal transfer of 96 ETH from the HongCoin contract to an investor address.
The top-level transaction value was 0 ETH because the actual movement happened inside the contract call.
Anyone following the money should separate eligibility from completed distribution. The contract state and multisig execution reopened a claim path for funds that had been inaccessible for years.
The visible on-chain examples show refund activity rather than a full accounting of every eligible investor’s claim.
The HongCoin case should be read carefully before anyone generalizes it to other old stuck funds. The ingredients were unusually specific: identifiable contract logic, an admin function still usable by the original control path, a whitehat willing to coordinate, and enough remaining on-chain value to make the effort worthwhile.
The practical detail is ownership and permission. The old function could change balances, but only the management path could call it.
That gives the recovery its ethical and operational boundary: outside research found the path, original signers executed it, and the claim route reopened for investors.
The same facts also make the case hard to generalize. Many dormant contracts lack an active control key, a clean claimant set, or a public trail that makes responsible recovery plausible.
That boundary also reduces the temptation to treat the episode as a broad exploit template. The technical mechanism explains why the refund gate reopened, but the story’s consequence comes from the combination of old code, living permissions, and public settlement.
Similar archaeology becomes riskier when a contract lacks one of those elements, because discovery can expose a weakness before it creates a usable recovery route.
Ethereum keeps the mistake and the remedy
The broader Ethereum history makes the HongCoin recovery more than a curiosity. A 2025 analysis citing Coinbase’s Conor Grogan put permanently lost ETH at more than 913,111, framed as a conservative estimate across user and contract-related errors.
That category includes funds sent to burn addresses, contract bugs, and major historical incidents.
Some of Ethereum’s most consequential early moments were also recovery debates. In 2016, the DAO hard fork moved roughly 12 million ETH from DAO-related contracts into a recovery contract after the network’s defining governance crisis.
In 2017, Parity Technologies’ multisig library self-destruct incident blocked 513,774.16 ETH across 587 wallets.
Those episodes were larger and politically heavier than HongCoin. They still help frame why this smaller recovery resonates.
Ethereum’s promise that code and state persist is a security property and a memory system. It preserves errors, half-forgotten assumptions, old permissions, and the occasional remedy whose future relevance was invisible at deployment.
That long memory now sits beside a maturing security culture. In January, Ethereum veterans announced plans to convert roughly 75,000 ETH in leftover TheDAO recovery funds into a staked endowment for Ethereum security.
The HongCoin case works on a much smaller scale, but points to the same afterlife of early Ethereum decisions.
The next test is recoverability: whether other old contracts contain paths that can be used responsibly. A white-hat recovery needs more than a bug. It needs a rightful control path, public on-chain evidence, careful disclosure, and a way to avoid turning contract archaeology into a playbook for opportunistic attacks.
HongCoin shows that some trapped funds can remain suspended inside old logic, waiting for someone to understand both the flaw and the permission structure around it. That is a hopeful result for the 48 investors now eligible to claim.
It is also a warning for the rest of the ecosystem: Ethereum remembers bad code, and sometimes it remembers the escape hatch too.
-
Technology1 week agoAnthropic co-founder urges for global oversight as AI threatens to displace human jobs ‘at a very large scale’ – Crypto News
-
Blockchain1 week agoThe Vast Majority of Crypto Wrench Attacks Happen in France: Report – Crypto News
-
others1 week ago
BMNR Stock Price Prediction as Tom Lee Says Bitmine Could Join Russell 1000 – Crypto News
-
Technology1 week ago
Crypto Weekly Recap: Crypto Reserve Bill, Trump’s Executive Order, SpaceX IPO Explained, Hyperliquid Hits ATH – Crypto News
-
Cryptocurrency1 week agoBitcoin price drop below $75K exposes the demand fracture behind crypto’s $941M liquidation wave – Crypto News
-
Technology1 week agoXiaomi 17T India launch date set: Expected price, display, camera and features – Crypto News
-
Blockchain1 week agoAmerican Mega Bank Is Dumping Its Ethereum Holdings, Here’s What It’s Buying – Crypto News
-
Blockchain1 week agoAnalyst Highlights Ethereum ‘Kill Zone’ That Shows The Best Time To Buy – Crypto News
-
others1 week agoBillionaire Bill Ackman Pours $2,092,970,000 Into One Asset, Dumps Uber and Two Mag 7 Stocks – Crypto News
-
others1 week ago
Why is NEAR Protocol Price Surging 30% Today? (May 22nd) – Crypto News
-
Blockchain1 week agoBitcoin LTH Supply Surge Does Not Reflect Real Demand — Here’s Why – Crypto News
-
others1 week ago
Ondo Finance Founder Nathan Allman Dies at 32 – What’s Next? – Crypto News
-
Business6 days ago
Mastercard Secures New York BitLicense To Support Stablecoin and Tokenization Services – Crypto News
-
Cryptocurrency1 week agoU.S. Congress launches insider trading probe into Polymarket, Kalshi – Crypto News
-
Blockchain1 week agoBitcoin Could Be Entering Critical Pullback Phase Below This Level – Crypto News
-
Technology1 week agoYour employer’s tracking software is quietly feeding your private data to Google, Microsoft and Meta, study finds – Crypto News
-
Business1 week ago
XRP News: Ripple Co-Founder Chris Larsen’s Wallets Become Active – Crypto News
-
Technology1 week ago
Ripple CTO Emeritus Defends Elon Musk’s X Amid Latest Lawsuit – Crypto News
-
Business1 week ago
Why is Dogecoin Price Not Rising? – Crypto News
-
others1 week ago
Ondo Finance Founder Nathan Allman Dies at 32 – What’s Next? – Crypto News
-
Business7 days ago
Ripple News: XRP Ledger Moves To Launch New Upgrade This Week – Crypto News
-
De-fi5 days agoSoFi Brings Its Bank-Issued Stablecoin to 14.7 Million Members – Crypto News
-
Cryptocurrency5 days agoDeFi’s automated yield protocols were built for retail, now they just add another layer of risk – Crypto News
-
De-fi5 days agoHave AI agents made the entire $148 billion DeFi sector unsafe? – Crypto News
-
Business1 week ago
CLARITY Act Approval Odds Drop Massively, What’s The Reason? – Crypto News
-
others1 week agoNexpace Announces NXPC Buyback Program to Reinforce User-Centered Ecosystem Growth in MapleStory Universe – Crypto News
-
Cryptocurrency1 week agoBitMine’s $126M Ethereum buy sets up a Russell index test tied to $12.2T in assets – Crypto News
-
Technology1 week agoThese premium tablet deals during Amazon Tablet Days deserve your attention – Crypto News
-
De-fi1 week agoTokenized Stocks Emerge as Fastest-Growing Asset Class on Ethereum – Crypto News
-
Metaverse1 week ago‘Orwell foretold in 1984’: How tech leaders, senators are reacting to Pope Leo’s encyclical on AI – Crypto News
-
Technology1 week ago
XRP Price Flashes Good Buy Signal amid Circle Acquisition Rumors: Santiment – Crypto News
-
Business1 week ago
Is Bitcoin Price at Risk of Crashing After Fresh US Strikes on Iran? – Crypto News
-
others7 days agoMorgan Stanley’s Mike Wilson Predicts S&P 500 Will Soar to 8,300 in Next 12 Months – Crypto News
-
Business7 days ago
Ethereum Treasury Sharplink (SBET) to Enter Russell 2000 & 3000 Indexes – Crypto News
-
Technology5 days agoMicrosoft Copilot, ChatGPT to Gemini: The AI productivity tools reshaping office work in 2026 – Crypto News
-
Technology5 days agoCloud war intensifies as Google ties enterprise deals to in-house AI – Crypto News
-
Cryptocurrency1 week agoXRP Exchange Reserve Drops to 2.70 Billion Amid Market Volatility – Crypto News
-
Business1 week ago
Bitget Kicks Off Second Year Supporting UNICEF’s Game Changers Coalition – Crypto News
-
Technology1 week agoWhy Mythos could be launching sooner than you think? Leaked code exposes preparations for Claude Mythos 1 – Crypto News
-
Technology1 week agoChinese startup claims it developed an AI collar that translates human words into barks and meows – Crypto News
-
De-fi1 week agoStablR Stablecoins Exploited, EURR and USDR Depeg After Minting Key Compromise – Crypto News
-
Cryptocurrency1 week agoBitMine’s $126M Ethereum buy sets up a Russell index test tied to $12.2T in assets – Crypto News
-
Technology1 week agoiPhone 18 Pro Max could maintain your 5G connection via satellite even while sitting in your pocket: here’s what we know – Crypto News
-
others1 week ago
AI Agents on Base Turn $1.5T SpaceX IPO Into 12-Minute Research Job – Here’s How – Crypto News
-
Blockchain1 week agoARIQO makes its Bangkok debut at SEABW, drawing industry attention – Crypto News
-
Blockchain1 week agoXRP Price Holds ‘Best Accumulation Zone’as Whales Pull $170M From Binance – Crypto News
-
Cryptocurrency1 week agoBitcoin Iran-deal rally faces its real test in oil flows and Fed pricing – Crypto News
-
Technology1 week ago
XRP Price Flashes Good Buy Signal amid Circle Acquisition Rumors: Santiment – Crypto News
-
Blockchain1 week agoAI Guardrail Removals Expose Gaps in Open‑Source Regulation – Crypto News
-
others7 days ago
BlackRock Bitcoin ETF Suffers $1.3 Billion Sale In Single Transaction – Crypto News






