Security Audit Flags High-Severity Vulnerabilities in HashKey Exchange Contracts
A DeFi security researcher published a vulnerability surface analysis of HashKey Exchange, a cross-chain decentralized exchange with approximately $1.73 billion in total value locked across Ethereum and several Layer 2 networks. The audit, dated September 24, 2026, examined smart contracts including the router, vault, pool, bridge adapters, and governance proxy components. Researchers identified nine vulnerability categories, with three rated high severity: a single externally owned account controlling contract upgrades without a timelock or multi-signature safeguard, re-entrancy risks in withdrawal and swap functions, and price oracle manipulation exposure on low-liquidity assets. Additional medium-severity issues include flawed cross-chain bridge message verification that could enable double-spend attacks, misconfigured access controls, and front-running risks on limit-order execution. The protocol received an overall risk score of 7 out of 10, with auditors noting that concentrated privileged control and the re-entrancy and oracle weaknesses significantly elevate its risk profile.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in