Login
Sign Up
Algorand-based privacy protocol HermesVault has permanently ceased operations following a security breach that resulted in the unauthorized transfer of approximately 261000 ALGO tokens. The incident, valued at roughly $29466 at the time of execution, was publicly confirmed by lead protocol engineer Giulio Pizzini via a detailed post on X. Pizzini clarified that the core zero-knowledge (zk) circuit underpinning the protocol's privacy mechanism remained uncompromised throughout the attack. Instead, the vulnerability resided within the key reset defense logic embedded in the withdrawal verification script. This specific implementation flaw enabled the attacker to bypass the mandatory zk verification process entirely, facilitating fund withdrawals without proper authorization. Data compiled by Woofun AI indicates that the technical distinction between the secure core circuit and the vulnerable auxiliary script was the primary vector for the exploit.
Following the discovery of the breach, the development team immediately patched the vulnerability to prevent further unauthorized access. A significant portion of the stolen assets, totaling 230000 ALGO, has already been returned to the project treasury.
However, 30000 ALGO remains unaccounted for, prompting the team to initiate a structured refund process for affected users. Victims who lost funds during the remaining 30000 ALGO theft are eligible for full compensation. To claim these funds, users must demonstrate ownership of their affected address and provide a secret note associated with their specific transaction. Woofun AI notes that while no specific deadline has been disclosed for refund claims, the team has urged users to act promptly to secure their assets.
The HermesVault incident highlights the intricate challenges inherent in securing privacy-focused decentralized finance protocols. Although zero-knowledge proofs are widely regarded as a robust cryptographic standard, implementation errors in surrounding logic layers, such as withdrawal scripts, can still expose critical vulnerabilities. This case serves as a stark reminder that even well-audited zk-based systems require comprehensive security reviews of all auxiliary components to ensure end-to-end integrity. Woofun AI analysis suggests that the divergence between theoretical cryptographic security and practical implementation logic remains a focal point for future protocol audits.
For the Algorand ecosystem, the shutdown of a notable privacy protocol raises significant questions regarding the long-term viability of privacy solutions on the network. This uncertainty is compounded by intensifying global regulatory scrutiny surrounding anonymous transactions. The closure of HermesVault following the $29K ALGO hack underscores the ongoing security challenges facing the decentralized finance sector. While the team acted swiftly to patch the flaw and initiate refunds, the incident has permanently ended the protocol's operations. Users with affected funds are encouraged to adhere strictly to the official refund process to recover their assets.