Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnAISquareMore
How Hinkal protocol’s smart contract flaw sparked $820K USDC exploit

How Hinkal protocol’s smart contract flaw sparked $820K USDC exploit

AMBCryptoAMBCrypto2026/07/04 13:03
By:AMBCrypto

Another day, yet another exploit.

News has been circulating that the Hinkal stablecoin privacy protocol may have been compromised. It appears that the suspected exploit was caused by a flaw in one of its smart contracts.

Reportedly, the flaw allowed an attacker to take about $820,000 worth of USDC out of the system.

@media only screen and (min-width: 0px) and (min-height: 0px) { div[id^="bsa-zone_1774359638628-7_123456"] { min-height: 50px; transition: min-height 0.3s ease; } } @media only screen and (min-width: 640px) and (min-height: 0px) { div[id^="bsa-zone_1774359638628-7_123456"] { min-height: 90px; } }
AD

Initial reports suggest the attacker extracted funds that should not have been accessible. The attacker was able to do this by manipulating Hinkal’s

prooflessDeposit(
) function and then making a string of
transact()
calls.

How Hinkal protocol’s smart contract flaw sparked $820K USDC exploit image 0 Source: GoPlus Security/X

Technique used to carry out the attack

Although the precise technical defect remains unknown, the attack suggests the protocol may have failed to validate deposits or verify the cryptographic proofs underpinning Hinkal’s privacy architecture.

This may have allowed the attacker to repeatedly call transact() and withdraw USDC held by the smart contract. As a result, a coding error led to a real financial loss.

That said, the suspected Hinkal exploit hints at a smart contract code vulnerability, which is one of the most enduring threats in decentralized finance (DeFi). While the incident does not point to a flaw in DeFi itself, it shows how implementation bugs can lead to significant financial losses.

Rise in exploits in 2026

This comes at a time when there have been other recent exploits. On the 20th of June, the Jaredfromsubway.eth Maximal Extractable Value (MEV) bot was exploited, which resulted in $7.5 million in losses.

In another instance, a hacker used a flash loan to manipulate the wrapped xStocks exchange rate, resulting in an approximately $403,000 exploit for Edel Finance. 

Taking all these together, it’s evident that scams have increased significantly in 2026. In fact, in the past six months, there have been 207 distinct hacks, according to TRM Labs.

Yet, despite the rise in incidents, DeFiLlama data showed that total losses came to $948.13 million, which is less than half of the $2.3 billion that was stolen in the first half of 2025.

How Hinkal protocol’s smart contract flaw sparked $820K USDC exploit image 1 Source: DeFiLlama

Final Summary

  • The Hinkal stablecoin privacy protocol exploit resulted in the compromise of $820,000 worth of USDC.
  • The attacker misused Hinkal’s prooflessDeposit() function and then made a string of transact() calls to carry out this attack. 
0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!

You may also like

As AI controversies escalate, hedge funds buy tech stocks at the fastest pace in 15 months

Hedge funds have recorded net purchases of US TMT stocks on 10 out of the past 11 trading days, rebuilding tech long positions at the fastest pace in 15 months. However, an AI policy storm has struck at the "worst possible time"—calls by AI giants to slow down development have been rejected, and regulatory uncertainty has directly hit Asian tech stocks such as Softbank. As the tech sector's bullish run coincides with Super Central Bank Week, the sector now faces a severe test.

华尔街见闻2026/09/14 07:03

Apple Pre-sale Tracker: iPhone 18 Pro Series Shows Weak Overseas Demand Signals, Duo Review Positive but Hardware Lags Behind

According to a survey by Jefferies, after the launch of the iPhone 18 Pro, delivery wait times in the four major markets—the US, UK, Germany, and Japan—have shortened by 5 to 11 days compared to last year, with no wait time in the US. Given stable production capacity, this is a clear sign of weak demand. Although the China and Hong Kong markets have performed better against the trend, there are still suspicions of speculative stockpiling. The new foldable Duo has been praised for its software experience, but its $2,000 price tag comes with a 254-gram body and dual-camera setup, leaving its hardware lagging significantly behind Android competitors. Jefferies maintains an "underperform" rating, with a target price implying a 21% downside from the current level.

华尔街见闻2026/09/14 06:42

UBS Health Benefit Survey: Elevance Health (ELV.US) Leads, U.S. Employers Prepare for Rising Medical Costs

In the annual survey by UBS for employee benefits management institutions, Elevance Health (ELV.US) emerged as the highest-rated US health insurance company.

智通财经2026/09/14 06:36
UBS Health Benefit Survey: Elevance Health (ELV.US) Leads, U.S. Employers Prepare for Rising Medical Costs