
More than 1,003.62 Ether worth approximately $2 million have been successfully recovered from a failed 2016 ICO dubbed Hong Coin after a white hat hacker identified a critical contract vulnerability. According to reports from The Block, the recovered ETH belonged to 48 investors who participated in the Hong Coin (HONG) token sale, a decentralized venture capital project that never launched after failing to meet its fundraising target. Blockchain records from Etherscan show that refunds have already begun, with two investors claiming 96.5 ETH valued at about $193,000, while another wallet recovered 0.5 ETH. The recovery represents a meaningful return for a case that originated in the 2016 ICO boom, demonstrating how persistent on-chain investigations can yield tangible results years after funds are deployed into questionable or poorly scripted smart contracts. As per The Block, the disclosure surfaced on Sunday via a post on X, where 0xflorent explained how the funds were unlocked and subsequently recovered from the project's fundraising participants.
The recovery became possible after white hat hacker 0xflorent identified an integer overflow flaw in the ICO contract's refund function. As explained by The Block, the contract was written in an old version of Solidity, the programming language used for Ethereum smart contracts, and lacked protections against integer overflow errors—a flaw where a number climbs high enough that it wraps back around to zero or one. The solution emerged from an overlooked administrative function that contained the integer overflow vulnerability, with specific input allowing the contract's refund conditions to execute correctly. 0xflorent described how they cooperated with the HONG creators, showing them how to extract the locked funds by exploiting the flawed admin function that resets token balances and triggers the refund check. The critical vulnerability lay in an admin function designed to administer token balances, which, when invoked with a crafted input, could reset a holder's balance and thereby unlock the refund mechanism that had otherwise been stuck in a dead end. According to The Block, the hacker described the root cause as an admin function with an integer overflow vulnerability, and when invoked with precise input, the function reset balances and effectively unblocked the refund check, enabling the retrieval of the locked funds.
The recovery was not a solo operation, as the admin function was locked behind the HongCoin team's multisig wallet, meaning the team had to sign off on every transaction. As reported by The Block, 0xflorent emailed the team, tested the fix on a copy of the network, and the team then signed 41 transactions—one for each blocked investor. The entire process took about a week to complete. Of the 48 eligible investors, 41 needed the balance reset, while the other seven held small enough amounts to be refunded directly. According to The Block, 0xflorent received no fee for the recovery—only voluntary "whitehat rewards" from two investors who appreciated the service. "There were no fees, no cut, no commission," 0xflorent told The Block, demonstrating the ethical approach of responsible disclosure in cryptocurrency security research.
Hong Coin was introduced in 2016 as a decentralized autonomous organization focused on venture capital investing, with a promotional video describing a structure where token holders would vote on projects that could receive funding from the community-managed pool. The ICO opened on August 29, 2016, and concluded on October 28, 2016, with participants contributing ETH expecting to receive a share of 250 million HONG tokens distributed across multiple funding stages. Because the project did not achieve its fundraising target, investors became eligible for refunds under the smart contract's rules, but the bug prevented these automatic refunds from processing. The Hong Coin ICO structure was straightforward on paper: ETH contributions would convert into 250 million HONG tokens distributed across five phases, with refunds to investors if the fundraising target was not met. The project dated back to 2016, a period when a flood of ICOs experimented with decentralized governance and venture-style capital allocation, leaving technical legacies that continue to pose challenges for safe unwinding when things go wrong. As per The Block, the HONG project was pitched as a community-driven venture capital fund governed by a decentralized autonomous organization, with the team describing the treasury and refund flow as central to the project's promise.
This recovery adds to a growing list of cases where white hat hackers have intervened to secure or return cryptocurrency funds after identifying vulnerabilities. According to Blockaid, a white hat attacker exploited a vulnerability in Renegade.fi's Arbitrum-based dark pool in May, temporarily draining about $209,000 before returning more than 90% of the assets. Beyond Hong Coin, 0xflorent has demonstrated his expertise through multiple successful recoveries, including 19.329 ETH worth approximately $40,590 from two previous contracts on May 24. The first involved a failed ICO in January 2018 that involved 5.141 ETH and an unnamed public refund function, while the second involved a Liquality Wallet user whose funds became trapped in a cross-chain transfer protocol after Liquality shut down its app in 2024. As reported by The Block, 0xflorent recently set up his own Ethereum node and built a scanner to find contracts holding more than 100 ETH, working through candidates to find exploitable flaws. These instances collectively illustrate how persistent on-chain investigations can yield tangible returns years after funds are deployed into questionable or poorly scripted smart contracts, with the Hong Coin episode highlighting the potential value of responsible disclosure and cooperative remediation when legacy contracts surface vulnerabilities after years of dormancy.