Suspected Hedera Exploit Sends $5.8M to Ethereum Network

Security researchers report a suspected Hedera exploit that bridged over $5.8M to Ethereum via LayerZero, prompting HBAR to dip. Analysts from Specter and PeckShield continue on-chain monitoring as investigations unfold.

Suspected Hedera Exploit Sends $5.8M to Ethereum Network
Reading time: 4 Minutes
Follow on Google

Suspected Hedera exploit moves millions to Ethereum amid HBAR dip

Blockchain security researchers have flagged a suspected exploit on the Hedera network that appears to have moved more than $5.8 million in digital assets to Ethereum. The event coincided with a dip in Hedera’s native token HBAR, which traded roughly 2% lower near $0.069 as on-chain observers tracked cross-chain transfers and token swaps.

What researchers have observed

Independent analyst groups Specter and PeckShield reported the large transfers after tracing a sequence of cross-chain bridges and swaps. According to their analysis, the attacker bridged substantial balances from Hedera to Ethereum using LayerZero infrastructure, then converted a significant portion of the funds from Wrapped Bitcoin (WBTC) into Ether (ETH).

Early alerts indicated that at least $3.7 million had already been bridged to Ethereum before further movements pushed the total to an estimated $5.8 million, based on wallet balances shared by on-chain monitoring services. The consolidated wallet reportedly holds a majority allocation in ETH, with a smaller position still denominated in WBTC.

On-chain trail and wallet indicators

Both Specter and PeckShield published the wallet addresses associated with the transfers and shared screenshots of inbound transactions that occurred over a short time window prior to conversion to ETH. PeckShield’s snapshot suggested the wallet contained roughly 2,360 ETH (valued at about $4.25 million at the time of reporting) alongside approximately 15.58 WBTC (around $1 million).

PeckShield also noted that the address’s initial funding included 1 ETH sourced from Tornado Cash, a detail visible in public transaction history. While on-chain provenance helps establish how funds moved, it does not identify the human operator behind the wallet or definitively prove culpability.

Market impact and ongoing monitoring

News of the suspected exploit exerted downward pressure on HBAR, contributing to the token’s short-term decline. Traders and investors watched social feeds and block explorers for updates as researchers continued to monitor the addresses and newly observed transfers. No official loss total or final accounting had been published at the time researchers issued their alerts, and reported figures updated as more assets were seen arriving on Ethereum.

Responses and investigation status

Neither Specter nor PeckShield attributed the activity to a specific actor, and Hedera’s official channels had not released a public statement detailing the cause or scope of the incident when the alerts were circulated. Security teams and market participants remain on alert, tracking bridge flows and decentralized exchange swaps where stolen funds are often converted into more liquid assets.

Because cross-chain bridges and messaging layers like LayerZero are central points in these flows, the event underscores persistent risks in multi-chain interoperability. Blockchain forensic teams are continuing to observe the wallets and will likely publish follow-up reports if suspects move funds through additional protocols or mixing services.

Context: broader security trends in crypto

This incident arrives amid several high-profile security disclosures across the cryptocurrency ecosystem. Recent weeks have seen exploit alerts involving other platforms — for example, Blockaid flagged an active exploit affecting Summer.fi, while a security breach led Ctrl Wallet to announce a permanent shutdown and an extended withdrawal window for affected Cardano users. Separately, governance discussions such as Secret Network’s proposal to migrate SCRT tokens from Cosmos to Arbitrum have cited security, liquidity, and codebase concerns as motivating factors.

These recurring incidents emphasize the need for robust smart contract audits, secure bridge designs, and real-time monitoring by exchanges and custodial services. For users, best practices remain: maintain small on-exchange balances, enable hardware wallets where possible, and watch for advisories from project teams and reputable security firms.

What to watch next

  • Official comment or incident report from the Hedera Foundation or operator teams.
  • Detailed forensic analyses from PeckShield, Specter, or other blockchain security firms explaining the exploit vector.
  • Any movement of the consolidated wallet through additional bridges, mixers, or decentralized exchanges.
  • Market reaction and whether HBAR stabilizes as updates are published.

As investigators piece together how the transfers occurred, the broader crypto community will be watching closely for signs of containment, recovery efforts, or further unauthorized asset flows. Continued transparency from projects, quick remediation, and coordinated responses from infrastructure providers are critical to reducing the impact of similar incidents in the future.

Elias Moreau

“I cover automotive innovation, electric vehicles, and the future of mobility — where technology meets sustainability.”

Leave a Comment

Comments (2)

Armin

Seems avoidable with better bridge designs. HBAR dip is dramatic tho, but will ppl learn? probably not, sigh

fundrift

Wait so billions didnt get hit but $5.8M moved? hmm... LayerZero again? feels fishy, anyone verified the bridge logs yet, or is this just wallet juggling