Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
  • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

Huma Finance V1 Exploit on Polygon Drains $101K in USDC

The project said its newer V2 system on Solana is unaffected because it was rebuilt from the ground up.

Written By:
Iyiola Adrian

Reviewed By:
Shubham Soni

Last updated: 30 minutes ago
Published 57 minutes ago
Share
Last updated: 30 minutes ago
Published 57 minutes ago
Huma Finance V1 Exploit on Polygon Drains $101K in USDC

Key Highlights

  • Huma Finance’s old V1 smart contracts on Polygon were exploited, resulting in a loss of about $101,400 USDC.
  • The attack was caused by a smart contract logic flaw in its function, which wrongly allowed unauthorized withdrawals from BaseCreditPool contracts.
  • The exploit was limited to legacy systems already being phased out, and Huma has now fully paused V1 while confirming user funds remain safe.

Huma Finance, a decentralized PayFi network, confirmed that a vulnerability in its legacy V1 smart contracts on the Polygon network was exploited on Monday, resulting in the loss of about 101,400 USDC.

In a post on X, the company said the incident only affected the older system and did not touch newer parts of the protocol. 

“No user funds at risk and PST is not impacted,” the team said, adding that its newer V2 system on Solana is a full rebuild that is not connected to this bug.

Earlier today a vulnerability in Huma’s legacy v1 contracts on Polygon was exploited for 101,400 USDC.

No user funds at risk and PST is not impacted. Huma’s v2 system on Solana is a complete rewrite and this issue does not apply to v2 systems.

The teams were already in the… https://t.co/DFjpamH2PW

— Huma Finance (@humafinance) May 11, 2026

How the attack happened

The attack happened in the V1 BaseCreditPool contracts, which are part of the older version of Huma Finance. According to Blockaid, a Web3 security firm that first reported the incident at around 3:10 PM UTC, the hacker was able to take advantage of a flaw in the contract code, which was inside a function called refreshAccount(). 

🚨 Exploit Alert – @humafinance V1 (deprecated)
✅ No user funds at risk.
Huma Finance's V1 BaseCreditPool deployments on Polygon were exploited a few minutes ago for ~$101K.

Total drained: ~$101.4K (USDC + USDC.e)

More Details:

— Blockaid (@blockaid_) May 11, 2026

The function wrongly changed an account status from “Requested credit line” to “GoodStanding” without checking properly. 

Because of this, the attacker was able to pass checks that should have blocked access and then withdraw funds from the system. Blockaid explained that about $101.4K worth of USDC and USDC.e was taken across multiple contracts linked to the V1 system.

Funds traced across contracts

Blockaid reported that one compromised contract, “0x3EBc1,” lost about 82,315.57 USDC, another “0x95533” lost 17,290.76 USDC.e, and a third “0xe8926” lost 1,783.97 USDC.e. The attacker’s address and exploit contract were also identified on-chain, and the movement of funds was tracked through PolygonScan records.

The exploit was carried out through a logic manipulation rather than a breach of cryptographic security. The attacker used the flaw to make the system think they were allowed to withdraw funds without doing enough extra checks.

Once the system wrongly approved them, they were able to pull out money from the treasury-linked pools. Everything happened in a single transaction, meaning it was done quickly and in one smooth operation.

V1 shutdown already in motion

Huma Finance said it had already been in the process of shutting down all V1 contracts before the exploit happened. Following the incident, the team fully paused V1 operations to stop any further risk. 

The company stressed that the newer V2 system is not affected because it was built from scratch with a different structure and improved safety design. User deposits and newer systems are reported untouched, and operations continue normally on the updated V2 platform.

DeFi exploits continue in 2026

The Huma incident adds to a growing list of DeFi exploits recorded this year. Earlier on the same day, INK Finance reportedly suffered a separate exploit involving $140,000. 

Other protocols, such as Kelp DAO, Drift Protocol, and Hyperbridge, have also experienced security incidents in 2026. 

So far, over half a billion dollars have been stolen from DeFi-related protocols in different exploits and hacks this year alone. Many of these incidents share a common theme: attackers are not breaking blockchain systems directly but instead targeting mistakes in smart contract design.

Also Read: Crypto Trader Drained of $200K in Telegram Bot Linked Crypto Hack

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Iyiola - Crypto Journalist at The Crypto Times
By Iyiola Adrian
Follow:
Iyiola is an experienced crypto writer specializing in simplifying complex blockchain and cryptocurrency topics for a broad audience. With expertise in ICOs, DeFi, NFTs, and regulatory updates, he offers valuable insights to help readers make informed decisions.
Shubham Soni Crypto Content Editor
By Shubham Soni
Follow:
Shubham Soni is a veteran content editor and journalist with over three years of experience leading digital editorial strategies across the U.S. and Indian markets. With a background in high-pressure newsrooms, Shubham specializes in the rigorous fact-checking, structural editing, and narrative development of complex news and explainers. Throughout his career at prominent digital publications like Sportskeeda and Opoyi, he has managed fast-paced desks covering global politics, sports, and entertainment. His expertise lies in transforming technical information into accessible, high-impact reporting while maintaining strict adherence to editorial ethics and accuracy. At The Crypto Times, Shubham oversees the editorial workflow, mentoring writers to ensure all cryptocurrency research and analysis meets the highest standards of clarity and journalistic integrity.

Latest News

Ondo Finance Surpasses $1B TVL in Tokenized Stocks and ETFs
Ondo Finance Surpasses $1B TVL in Tokenized Stocks and ETFs
CIP-86 Passed: CoW DAO Begins Compensation for April Attack
CIP-86 Passed: CoW DAO Begins Compensation for April Attack
Cosmos Hub Adopts Injective USDC as Primary Stablecoin
Cosmos Hub Adopts Injective USDC as Primary Stablecoin
Multi-Chain Wallet Breach Drains $665K Across 50+ Victims Cluster
Multi-Chain Wallet Breach Drains $665K Across 50+ Victims Cluster
MoonPay Builds AI-Powered Trading Stack Through Dawn Labs Deal
MoonPay Builds AI-Powered Trading Stack Through Dawn Labs Deal

Find Us on Socials

You may also like

Ondo Brings Wall Street Stocks to Hyperliquid’s DeFi Ecosystem

Ondo Brings Wall Street Stocks to Hyperliquid’s DeFi Ecosystem

Ripple Prime Unlocks $200M to Fuel Crypto and TradFi Lending

Ripple Prime Unlocks $200M to Fuel Crypto and TradFi Lending

Peter Schiff Fires Back at Saylor Calls STRC a ‘Classic Centralized Ponzi Run by MSTR’

Peter Schiff Fires Back at Saylor: Calls STRC a ‘Classic Centralized Ponzi Run by MSTR’

Galaxy Digital and Sharplink to Launch $125M Institutional Onchain Yield Fund

Galaxy Digital and Sharplink to Launch $125M Institutional Onchain Yield Fund

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information