Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Gold Bitcoin BTC coin standing vertically in front of a rising green financial candlestick chart
    Inside Bitcoin’s September 2026 Rally: BTC Reclaiming $87K, $2B in ETF Inflows and a Short Squeeze
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
    3D Liquid Network logo with a hooded hacker shadow and computer code overlays in the background
    Liquid Network Exploit Explained: Unbacked L-BTC and the $320M Peg-Out
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

INK Finance Exploited on Polygon, $140K USDT Drained in Flash Loan Attack

Blockaid revealed that attackers exploited a whitelist validation flaw in INK Finance’s Workspace Treasury Proxy on Polygon, using a $25,000 flash loan to drain roughly $140,000 in USDT.

Written By Dishita Malvania
Published 2026-05-11
Make The Crypto Times preferred on GoogleGoogle
INK Finance Exploited on Polygon, $140K USDT Drained in Flash Loan Attack
Show AI Summary
Blockaid, a Web3 security firm, identified and alerted the community to the INK Finance security incident
INK Finance’s Workspace Treasury Proxy contract was exploited due to a logic flaw in its authentication process
The attacker exploited the flaw by deploying a malicious contract that mimicked a whitelisted claimer entry in INK Finance’s Workspace controller

DeFi governance infrastructure platform INK Finance has confirmed a security incident on its Polygon deployment, with its Workspace Treasury Proxy exploited for roughly $140,000 in USDT earlier today. 

The breach was first surfaced by Web3 security firm Blockaid at around 1:41 PM UTC on May 11, 2026, in a community alert that flagged the victim contract, attacker address, and the exploit transaction on Polygonscan.

The compromised contract sits at 0xa184Af4B1c01815A4B57422A3419E4FB78a96Ee4, identified on-chain as INK Finance’s Workspace Treasury Proxy. The proxy is an EIP-1967 beacon pattern contract that was originally deployed in December 2023, and routes calls through a shared implementation at 0x72225ccb…7AFc89890. The treasury sat dormant until the exploit transaction landed earlier today.

INK Finance has positioned itself for years as Web3’s “gold standard” for DAO financial infrastructure, offering treasury management, governance flows, and on-chain payment modules across Avalanche and Polygon. Today’s incident strikes directly at the treasury layer that the protocol’s entire pitch is built on.

How the exploit worked

According to Blockaid’s post-incident breakdown and on-chain forensics, the attacker did not break cryptography or steal a key. They exploited a logic flaw in INK’s Workspace controller, specifically in how the controller authenticates accounts permitted to call its claim() function.

The vector unfolded in three steps:

Step one. The attacker deployed a malicious contract at an address that matched, or was registered as, a whitelisted claimer entry inside INK Finance’s Workspace controller. Whitelisted-claimer logic is a common DeFi pattern that allows pre-approved addresses to claim or execute on behalf of users, often to enable atomic claim-and-stake or claim-and-forward flows. 

The integrity of the pattern depends entirely on the whitelist being tightly bound to trusted entities, which, in this case, it was not.

Step two. Once the attacker controlled an address that passed the whitelist check, they invoked claim(claimId) on the controller. The function ran its eligibility check, found the caller in the allowed set, and signaled approval downstream. 

The treasury proxy’s authorized transfer function trusted that approval implicitly and released funds without applying any additional ownership or balance-sanity gate.

Step three. To inflate the payout, the attacker pulled a roughly $25,000 flashloan from Balancer V2, used it inside the same transaction to satisfy whatever balance condition the claim path was checking, drained approximately $140K USDT from the Workspace Treasury Proxy, and repaid the flashloan in the same atomic call. 

The flashloan piece turned a logic flaw into a profitable extraction, since it let the attacker temporarily appear to be a much larger eligible claimant than they actually were.

The malicious actor contract is logged at 0x90b147592191388e955401af43842e19faa87ee2, and the exploit transaction is publicly viewable on Polygonscan.

Funding trail points to railgun

Blockaid’s trace of the attacker’s wallet’s funding history reveals a textbook obfuscation chain. The wallet was funded via Railgun on Ethereum, the privacy-preserving smart-contract system that shields sender, receiver, and amount metadata, before the funds were bridged over to Polygon roughly 32 minutes before the exploit transaction landed. 

The short delta between bridging and exploit suggests the attacker had the contract pre-staged and was simply waiting for gas and capital to be in position.

Railgun has become an increasingly recurrent footprint in post-exploit forensic write-ups over the past year, in many cases functioning as the modern successor to Tornado Cash for attackers who want privacy without the regulatory baggage of sanctioned mixers.

What it means

The $140K figure is small in dollar terms compared to the eight and nine-figure exploits that have defined recent DeFi quarters, but the class of vulnerability is the larger story. Whitelist-gated claim functions, paired with proxy-based treasuries, are deployed across a meaningful slice of DAO infrastructure today. 

The exploit is essentially a textbook case of an authorization check that confirms who is calling without re-validating what they are entitled to receive, and it generalizes uncomfortably well to other treasury controllers built on the same pattern.

A few specific observations stand out for protocols running similar architectures:

The Workspace Treasury Proxy was an unverified contract on Polygonscan at the time of the exploit, which limited the ability of external auditors and white-hat researchers to spot the flaw pre-incident. The implementation it points to has been live since 2023 without further upgrades on this proxy, meaning the vulnerable logic has been on-chain and exploitable for an extended window.

The flashloan-assisted nature of the attack also reinforces a pattern that has played out repeatedly across DeFi exploits: as long as a contract’s authorization or accounting logic is sensitive to caller balances or token holdings at the moment of the call, attackers will rent that balance from Balancer, Aave, or Morpho for the length of a single transaction and walk away with the payout.

What’s next

INK Finance has not, at the time of this report, posted a formal public statement on its own channels detailing the scope, remediation timeline, or whether user funds beyond the drained Workspace are at risk. Blockaid has tagged the attacker address and the exploit transaction publicly, which typically precedes coordinated outreach with centralized exchanges and bridges to flag the funds if they attempt to move further.

For users with active INK Finance Workspaces or treasury setups on Polygon or Avalanche, the prudent stance until INK issues guidance is to revoke any outstanding approvals to the Workspace controller and treasury proxy contracts, audit current claimer whitelists for any unfamiliar entries, and avoid deploying fresh capital into INK-managed treasuries until a post-mortem and patch are confirmed on-chain.

The Crypto Times will continue to track the incident and update this report as INK Finance, Blockaid, and on-chain investigators publish further findings.

Also Read: 40+ DeFi Protocols Shut Down in 2026: Inside the $770M Hack Crisis Reshaping Crypto

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Crypto HackPolygonTether
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Black Revolut metal debit card with white embossed branding logo set against a textured geometric background
Revolut Data Breach Notices Hit Former US Trading Users as DriveWealth Confirms Hack: What Was Exposed
Silver crypto token coin featuring a dark abstract fluid logo crashing down near a declining red market chart
HYPE Price Slips Below $90 After Binance Opens Spot Trading
Smartphone displaying Payy app logo on a bright lime-green screen held in hand
$1.83 Million in USDC Leaves Payy Network’s Ethereum Rollup Contract
XRP token coin standing upright against a declining red candlestick market chart background
XRP Price Falls 8.5% to $1.46 as Traders Sell Despite $18M in ETF Inflows
Donald Trump positioned between Strategy and Coinbase company logos
Trump Ethics Filing Shows July Buys of Strategy (MSTR) and Coinbase (COIN) Stocks

Find Us on Socials

You may also like

Polygon (POL) crypto coin set against a trading chart dashboard.

Polygon Burns 100M POL, Cutting 1% of Supply

A cracked red coin bearing the QiDao logo standing in front of a Polygon logo and a price chart dropping to $0.85.

QiDao’s MAI Falls to $0.85 on Polygon as Depeg Continues

Sonic Cancels All Manual S Token Mints and Orders Independent Audit

Sonic Cancels All Manual S Token Mints and Orders Independent Audit

A hat-wearing figure at a laptop in front of a Coldcard wall logo.

52.37 BTC From Coldcard Exploit Moved Into Wyoming Recovery Trust for Victim Return

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information