Wednesday, May 20, 2026
cryptonews100
No Result
View All Result
CryptoNews100
No Result
View All Result
Home Uncategorized

Huma Finance legacy V1 contract on Polygon exploited for $101,400 USDC

cryptonews100_tggfrn by cryptonews100_tggfrn
May 12, 2026
in Uncategorized
0
Huma Finance legacy V1 contract on Polygon exploited for $101,400 USDC
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
Sign up an get up to $1000 USDT!


A logic bug in Huma’s legacy V1 Polygon credit score swimming pools let an attacker drain about $101,400 in USDC, however its Solana‑based mostly PayFi V2 and PST token stay structurally unaffected.

Abstract

  • Huma says deprecated V1 BaseCreditPool contracts on Polygon have been exploited for roughly $101,400 in USDC and USDC.e as they have been being wound down, whereas its dwell PayFi V2 on Solana was untouched.
  • Blockaid traces the loss to a refreshAccount() logic flaw that flipped borrowers into “GoodStanding” without proper checks, letting the attacker withdraw from treasury‑linked pools in a single, scripted transaction.
  • All remaining V1 contracts on Polygon are now paused, with Huma stressing that current deposits and PST positions on Solana’s rebuilt, permissionless PayFi architecture are separate from the vulnerable V1 code.

Huma Finance has disclosed that its legacy V1 contracts on Polygon were exploited, with roughly $101,400 in USDC and USDC.e drained from old liquidity pools that were already in the process of being wound down. The team stressed that no user deposits on its current PayFi platform are at risk, Huma’s PST token was not impacted, and its re‑architected V2 system on Solana is structurally separate from the affected contracts.

According to an official post on X, “Huma Finance’s V1 BaseCreditPool deployments on Polygon were exploited … for ~$101K. Total drained: ~$101.4K (USDC + USDC.e),” with the team confirming that the incident was confined to deprecated contracts rather than live production vaults. A detailed write‑up from Web3 security firm Blockaid, cited by CryptoTimes, attributes the loss to a logic flaw in a function called refreshAccount() inside the V1 BaseCreditPool contracts, which incorrectly changed an account’s status from “Requested credit line” to “GoodStanding” without sufficient checks.

That bug let the attacker bypass access controls and withdraw funds from treasury‑linked pools as if they were an approved borrower. Blockaid’s evaluation reveals about 82,315.57 USDC drained from one contract (0x3EBc1), 17,290.76 USDC.e from one other (0x95533), and 1,783.97 USDC.e from a 3rd (0xe8926), all in a tightly orchestrated sequence that executed in a single transaction. The exploit didn’t contain breaking cryptography or personal keys, however slightly manipulating enterprise logic so the system “thought” the attacker was allowed to tug funds.

Huma says it had already been phasing out its V1 liquidity swimming pools on Polygon when the exploit occurred, and has now totally paused all remaining V1 contracts to stop any additional danger. In its disclosure, the staff emphasised that Huma 2.0 — a permissionless, composable “actual‑yield” PayFi platform that launched on Solana in April 2025 with assist from Circle and the Solana Basis — is “a whole rebuild” with a unique structure and isn’t related to the susceptible V1 code.

Huma 2.0’s design facilities on the $PST (PayFi Technique Token), a liquid, yield‑bearing LP token that represents positions in cost‑financing methods and will be built-in with Solana DeFi protocols equivalent to Jupiter, Kamino and RateX. Against this, the exploited V1 contracts have been a part of an older, permissioned credit score‑pool system on Polygon, now successfully retired.

For customers, the important thing takeaway is that the roughly $101,400 USDC loss hit legacy protocol‑degree liquidity slightly than particular person wallets, and that present deposits and PST positions on Solana are reported as secure. Nonetheless, the incident provides one other instance to a protracted checklist of DeFi exploits the place the weak level was not signature schemes however enterprise logic in growing older contracts — reinforcing why groups like Huma are migrating to redesigned architectures, and why customers ought to deal with “legacy” and “quickly to be deprecated” swimming pools with the identical warning they reserve for unaudited code.



Source link

Related articles

XRP Sits at $1.47 Inside a Tightening Triangle — A Daily Close Above $1.529 Could Unlock a Fast Path to $1.80

XRP Sits at $1.47 Inside a Tightening Triangle — A Daily Close Above $1.529 Could Unlock a Fast Path to $1.80

May 12, 2026
Huma Finance V1 Exploit on Polygon Drains $101K in USDC

Huma Finance V1 Exploit on Polygon Drains $101K in USDC

May 12, 2026
Tags: contractExploitedfinanceHumaLegacyPOLYGONUSDC
Share76Tweet47
Drive and walk to earn crypto!

Related Posts

XRP Sits at $1.47 Inside a Tightening Triangle — A Daily Close Above $1.529 Could Unlock a Fast Path to $1.80

XRP Sits at $1.47 Inside a Tightening Triangle — A Daily Close Above $1.529 Could Unlock a Fast Path to $1.80

by cryptonews100_tggfrn
May 12, 2026
0

XRP is approaching a second of reckoning. After months of grinding compression between descending resistance and rising assist, the token...

Huma Finance V1 Exploit on Polygon Drains $101K in USDC

Huma Finance V1 Exploit on Polygon Drains $101K in USDC

by cryptonews100_tggfrn
May 12, 2026
0

Key Highlights Huma Finance’s previous V1 sensible contracts on Polygon had been exploited, ensuing in a lack of about $101,400...

Polygon Price Prediction After Visa Settlement: POL Hits 3,800

Polygon Price Prediction After Visa Settlement: POL Hits 3,800

by cryptonews100_tggfrn
May 12, 2026
0

The polygon worth prediction turned when Polygon landed Visa as a stablecoin associate and pushed its pace to 3,800 transactions...

Polymarket vs. Kalshi: The Key Differences Between the Two Biggest Prediction Markets

Polymarket vs. Kalshi: The Key Differences Between the Two Biggest Prediction Markets

by cryptonews100_tggfrn
May 11, 2026
0

In the event you're attempting to select between prediction markets, Polymarket and Kalshi are the two largest names in 2026....

POL Tests $0.11 After Visa Stablecoin

POL Tests $0.11 After Visa Stablecoin

by cryptonews100_tggfrn
May 11, 2026
0

Visa simply added Polygon to its stablecoin settlement program, and the polygon value prediction shifted the second that announcement dropped....

Load More

Crypto Fear & Greed Index

Latest Crypto Fear & Greed Index

Recent News

Knox County commission works to regulate data centers before more arrive

Knox County commission works to regulate data centers before more arrive

May 20, 2026
South Korean Funeral Company Faces $33M Unrealized Loss on Leveraged Ether ETFs

South Korean Funeral Company Faces $33M Unrealized Loss on Leveraged Ether ETFs

May 20, 2026
Measuring Bitcoin’s Quantum-Exposed Supply

Measuring Bitcoin’s Quantum-Exposed Supply

May 20, 2026

Categories

  • Bitcoin
  • Cardano
  • Chainlink
  • Cryptocurrency
  • Dogecoin
  • Ethereum
  • Exchanges
  • HYPE
  • Ondo
  • Real World Assets
  • Shiba Inu
  • Solana
  • sui
  • Uncategorized
  • World Liberty Financial
  • XRP

Download the official CryptoNews100 Android App! Click the button below:

Tags

Bitcoin (83) blockchain (20) Breakout (15) BTC (16) Cardano (18) ChainLink (18) crypto (131) Cryptocurrency (29) Dogecoin (23) ETF (19) ETH (21) Ethereum (52) Expands (16) eyes (18) Heres (17) Hyperliquid (27) key (16) launches (29) market (46) MATIC (26) million (23) Network (19) News (58) Ondo (23) payments (19) PEPETO (28) POL (21) POLYGON (124) prediction (84) Presale (17) price (105) Recovery (18) Solana (37) Stablecoin (29) Sui (21) support (20) targets (19) token (20) Tokenized (18) top (31) trading (17) TradingView (19) Trump (18) USDC (20) XRP (48)

© 2023 Crypto News100 All Rights Reserved.
By visiting this website, you understand that the content provided within is for educational and entertainment purposes only. Nothing on this site may be constituted as financial advice and this site is not directing you to make any investments in cryptocurrency or in anything else. Thank you for visiting and please proceed responsibly.
As an Amazon Associate I earn from qualifying purchases.

No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Alt Coins
    • Cardano
    • Dogecoin
    • HYPE
    • Shiba Inu
    • Solana
    • XRP
  • Crypto Related DEALS

© 2023 Crypto News100 All Rights Reserved.
By visiting this website, you understand that the content provided within is for educational and entertainment purposes only. Nothing on this site may be constituted as financial advice and this site is not directing you to make any investments in cryptocurrency or in anything else. Thank you for visiting and please proceed responsibly.
As an Amazon Associate I earn from qualifying purchases.