Hacken Token Crashes and Investor Loses $860,000 in Separate Crypto Scandals
0
0
In two alarming crypto incidents, cybersecurity firm Hacken saw its $HAI token plunge by nearly 98% after a private key leak enabled unauthorized minting, while a Florida investor claimed in a federal lawsuit that he was scammed out of $860,000 by a Denver-based crypto training center and a fraudulent exchange.Â
Private Key Leak Crashes Hackenâs $HAI Token by 98%: CEO Blames Human Error and Promises Compensation Plan
Ukrainian cybersecurity firm Hacken is facing a crisis of confidence after the firm revealed a critical private key leak allowed an attacker to mint nearly 900 million of its native $HAI tokens, decimating the tokenâs value by nearly 98% at one point. The exploit, which occurred on both Ethereum and Binance Smart Chain (BSC), caused a rapid sell-off that tanked $HAIâs market capitalization from roughly $12.7 million to $7.2 million, according to CoinGecko data.
HAI price chart (Source: CoinGecko)
The breach stemmed from the compromise of a private key associated with an account that held âminterâ privilegesâallowing it to create new tokens at will. Hacken confirmed the exploit in a statement on X (formerly Twitter) on Saturday, noting that the attacker managed to mint hundreds of millions of tokens and dumped them on decentralized exchanges on the BSC network.
âA private key of an account with a minter role (ETH & BNB) was compromised, leading to unauthorized HAI minting and a dump on BSC DEXs,â Hacken wrote. While the attacker is believed to have made off with around $250,000 in illicit gains, the real damage came from the hyperinflationary impact of doubling the tokenâs total supply in a matter of minutes.
A Price Collapse and Attempted Recovery
The price of $HAI plummeted by as much as 97% in the immediate aftermath of the exploit, triggering panic among holders. The token saw a modest rebound on Sunday but remains well below its pre-exploit levels. The incident sent shockwaves through the cybersecurity and Web3 communities, not only because of the scale of the attack but because of the symbolic ironyâHacken is, after all, a firm that advises projects on how to avoid precisely this type of vulnerability.
In an unusually candid admission, Hackenâs co-founder and CEO Dyma Budorin took full responsibility for the incident, blaming the breach on a long-standing failure to upgrade the firmâs infrastructure with multi-signature protection for sensitive accounts.
âResponsibility is on me,â Budorin wrote on X. âI didn't implement multisig bridge [infrastructure] 5 years ago. I understood the risk, but delayed bridge restructuring due to not unimportant reasons.â
The company has since regained control by using its deployer walletâwhich was not compromisedâto revoke minting permissions from the affected accounts.
To address the damage, Hacken is now planning a potential token swap that could help affected users recover losses. On social media, the team hinted at a larger restructuring effort involving what it called a âbig merge between $HAI and Hacken equity shareholders,â which it claims is valued at over $100 million.
While the full details of the compensation plan have not yet been released, the company said a comprehensive post-mortem will follow once the internal investigation is complete.Â
A Case Study in Web3 Security Failures
The breach comes just weeks after Hackenâs own Q1 Web3 security report warned that human error and misconfigured access controls represent the most significant threat vectors in the decentralized ecosystem. The report cited $1.6 billion in damages caused by such vulnerabilities in Q1 alone, noting that while smart contract bugs still pose a risk, âmost damage is now caused by failures in people, processes, or permission systems.â
This incident painfully illustrates that point. Even firms dedicated to blockchain security can fall prey to the very weaknesses they warn others about.
Florida Investor Alleges $860K Scam Involving Fake Crypto Exchange and Denver-Based Trading âSchoolâ
Meanwhile, a Florida man says he was duped out of $860,000 by a crypto trading scam involving a Denver-based education firm and a fraudulent crypto exchange that promisedâand simulatedâlife-changing profits, only to ultimately vanish his funds behind a so-called system error.
In a lawsuit filed last week in a federal court, investor Brian Firestone alleged that the Alpha Stock Investment Training Center (ASITC) and a fraudulent crypto exchange called CoinBridge Partners orchestrated an elaborate scheme that led to devastating financial loss. The trading âschool,â which operated out of downtown Denver, reportedly coordinated the scam using a now-defunct website and a fake exchange address in Cherry Creek, Colorado.
Firestone lawsuit against Alpha Stock Investment Training Center (Source: Justia)
The Pitch: Education, Signals, and a $500 Hook
According to the suit, Firestone was first contacted in December 2024 by a man identifying himself as John Smith, a representative of ASITC. Smith offered to teach cryptocurrency trading and provided Firestone with a $500 âstarter giftâ to begin learning signal-based crypto strategies.
Signal trading involves following precise, real-time instructions from experts, or âprofessors,â to make specific trades. Firestone said ASITC professors would send him messages with exact times and amounts to buy or sell crypto, and he would carry out these instructions using his account on CoinBridge.
Initially, the results were astonishing. Firestone claims that his $500 quickly grew to $55,000, prompting him to invest $50,000 more in January. Within weeks, his CoinBridge account allegedly ballooned to $2 million.
But the rapid gains soon turned into devastating losses. According to the lawsuit, a failed trade reduced Firestoneâs balance to just $12,000, leading him to wire $470,000 more in cash and take out a $330,000 loan from ASITC to continue trading. Following this, his account reportedly surged to $24.5 million.
However, things took a suspicious turn on March 9 when a trade in Tether (USDT) failed to execute. Firestone frantically messaged Smith saying: âI canât close it... I ncant clpsoe it.â The response was that a âsystem errorâ had caused the glitch, and his entire balance vanished overnight.
In a final desperate bid to recover, Firestone says he borrowed another $1 million from ASITC, raising his account balance to $6.6 million. But when he was unable to repay part of his loan, ASITC allegedly shut down his CoinBridge account on May 1, cutting off access to all funds.
Allegations of Fraud and a Fake Exchange
Firestoneâs lawsuit accuses ASITC, CoinBridge, John Smith, and ASITC founder Raymond Torres of fraud, theft, and racketeering, alleging the entire operation was a coordinated scam. The suit describes CoinBridge as a completely fictitious crypto exchange with fabricated investor figures and no legitimate regulatory standing.
Although a real entity named CoinBridge Partners exists in Wyoming, it has denied any connection to the accused parties or the operation in Denver.
Firestoneâs ordeal highlights a broader trend in crypto-related fraud. According to blockchain security firm CertiK, over $2.1 billion has already been stolen in 2025 through various crypto scams, with a significant portion stemming from social engineering, wallet mismanagement, and fake platforms rather than traditional smart contract vulnerabilities.
CertiK co-founder Ronghui Gu emphasized that the rise in human-centered attacks marks a shift in the threat landscape: âWhile code-based exploits still exist, most attackers are now focusing on user behaviorâexploiting trust, confusion, and urgency.â
In 2024, phishing attacks alone led to more than $1 billion in damages across nearly 300 incidents, making it the most damaging attack vector in crypto security. Many of these scams used fabricated trading dashboards, AI-generated support agents, and deepfake communications to fool users into making irreversible transfers.
Questions Remain as Authorities Investigate
The ASITC website and CoinBridge platform have since gone offline, and both appear to have scrubbed their digital footprints. The physical address listed on ASITCâs websiteâ1660 Lincoln St., Denverânow leads to a co-working space with no visible connection to crypto training.
The lawsuit is expected to move forward as federal authorities begin investigating the financial and digital paper trails behind the scheme.
0
0
Securely connect the portfolio youâre using to start.
