Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
No Result
View All Result
Home News Security & Hacks

INK Finance Suffers $140K Drain on Polygon: Attacker Exploits Treasury Proxy via Whitelist Flaw and Flash Loan

Attackers exploited a weakness in INK Finance’s treasury proxy validation system, using a flash loan to siphon nearly $140,000 USDT in a single Polygon transaction.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
May 11, 2026
in Security & Hacks
0 0
INK Finance Suffers $140K

Created By Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

Decentralized finance never sleeps, and even platforms designed for secure treasury management can sometimes get caught off guard. On May 11, 2026, INK Finance became the latest project to suffer a security breach when an attacker drained roughly $140,000 in USDT from its Workspace Treasury Proxy contract on the Polygon network. Security firm Blockaid was the first to flag the incident.
What makes this exploit stand out is its clean and methodical execution rather than the size of the haul. The attacker didn’t steal private keys or tamper with oracles. Instead, they took advantage of a flaw in the whitelist validation and smartly combined it with a flash loan to drain the funds in a single transaction.

🚨 Community Alert@inkfinance‘s Workspace Treasury Proxy on Polygon was exploited a few minutes ago for ~$140K.

More details in🧵

— Blockaid (@blockaid_) May 11, 2026

What is INK Finance?

INK Finance is a multichain platform designed to serve as a financial operating system for DAOs, protocols, and Real World Asset projects. It provides tools for on-chain treasury management, governance, payments, fundraising, and compliance.

The platform allows teams to create customizable “workspaces” with different committees for treasury, investments, and community decisions. Its core offering includes the Universal Custodian Vault and Workspace Treasury Proxy, which many DAOs use to handle authorized transfers efficiently. The project is mainly active on Polygon and Avalanche.

The compromised contract (0xa184…96Ee4), an EIP-1967 beacon proxy deployed in late 2023, was the target of today’s attack.

How the Exploit Happened

According to initial findings from Blockaid and other security researchers, the attacker executed a precise and well-planned attack by following these key steps in a single atomic transaction:

  • Deployed a Malicious Contract: The attacker first created and deployed a malicious smart contract that was carefully designed to satisfy the whitelist criteria in INK Finance’s Workspace controller. This allowed the contract to appear as a legitimate, pre-approved claimer.
  • Triggered the Claim Function: Using this malicious contract, the attacker then called the claim(claimId) function on the controller. Because the whitelist check was passed successfully, the request moved forward and triggered an authorized withdrawal from the Workspace Treasury Proxy without raising any red flags.
  • Used a Flash Loan for Amplification: To meet any required balance or collateral conditions inside the claim process, the attacker borrowed approximately $25,000 through a Balancer V2 flash loan within the same transaction. This temporary capital boost enabled the full drainage of around $140,000 in USDT. Once the funds were extracted, the flash loan was automatically repaid before the transaction concluded.

The full exploit transaction can be viewed on Polygonscan: 0xb469…6b982

Attacker address: 0x90b1…87ee2

Funding Trail

On-chain data shows the attacker received funds through Railgun on Ethereum for privacy before bridging to Polygon just 32 minutes before executing the exploit. This suggests the attack was carefully prepared in advance.

Current Situation and Advice for Users

INK Finance has acknowledged the incident, though a complete technical post-mortem and recovery plan have not yet been released.

Users and DAOs with active workspaces on Polygon or Avalanche are strongly advised to:

  • Immediately revoke approvals tied to affected controller and proxy contracts.
  • Audit all whitelisted claimer addresses and permissions.
  • Monitor official INK Finance announcements before moving treasury assets.
  • Increase monitoring for unusual proxy interactions or sudden treasury withdrawals.

Broader Implications

While a $140K loss is relatively small compared to some of the larger DeFi hacks seen in 2026, this incident once again highlights a persistent weakness across decentralized finance: flawed authorization logic inside treasury systems.

Whitelist-based mechanisms remain convenient for DAO operations, but they can become dangerous when protocols fail to re-validate transaction amounts, ownership, or destination addresses during execution. Similar vulnerabilities have also surfaced in other protocols, including the Aftermath Finance exploit, where attackers reportedly drained more than $1.14 million through weaknesses tied to smart contract execution logic.

The INK Finance incident serves as another reminder that security in DeFi is not a one-time checklist. Continuous audits, layered permission controls, real-time monitoring, and stricter validation mechanisms are becoming essential for protecting on-chain treasury infrastructure.

As the DeFi ecosystem matures, both builders and users will need to remain proactive and vigilant against increasingly sophisticated exploit strategies.

Disclaimer: Cryip is an independent media and research outlet providing news, data, and analysis on the cryptocurrency industry. Content is for informational and research purposes only and does not constitute financial, legal, tax, or investment advice. Cryptocurrency markets are volatile and past performance is not indicative of future results. References to specific assets, platforms, or incidents are for journalistic purposes only and do not imply endorsement, and readers assume full responsibility for their decisions.
Tags: Crypto HacksPolygon

Related Posts

RetoSwap Suspends Trading Following Second Exploit in Haveno Protocol
Security & Hacks

RetoSwap Suspends Trading Following Second Exploit in Haveno Protocol

by Saravana Kumar Mahendran
June 17, 2026

RetoSwap, a leading privacy-focused peer-to-peer decentralized exchange for trading Monero (XMR) against fiat and other cryptocurrencies over Tor, has temporarily...

Read moreDetails
Humanity Protocol to Replace Compromised $H Tokens With New ERC-20 Airdrop

Humanity Protocol to Replace Compromised $H Tokens With New ERC-20 Airdrop

June 16, 2026
Polygon zkEVM Sunset Deadline Nears as Users Urged to Withdraw Assets Before July 1, 2026

Polygon zkEVM Sunset Deadline Nears as Users Urged to Withdraw Assets Before July 1, 2026

June 16, 2026
Thetanuts Finance Hit by $2.1M Exploit as Legacy Ethereum Vault Flaw Resurfaces

Thetanuts Finance Hit by $2.1M Exploit as Legacy Ethereum Vault Flaw Resurfaces

June 16, 2026
Aztec Connect Exploit Drains $2.19M From Deprecated Protocol, Aztec Network Safe

Aztec Connect Exploit Drains $2.19M From Deprecated Protocol, Aztec Network Safe

June 15, 2026 - Updated on June 16, 2026
Humanity Protocol Hack Linked to North Korean Actors as Quantstamp Investigation Reveals $36M Exploit

Humanity Protocol Hack Linked to North Korean Actors as Quantstamp Investigation Reveals $36M Exploit

June 13, 2026
Raydium Suffers $1.34M Exploit as Attacker Drains Dormant Legacy AMM V3 Liquidity Pools on Solana

Raydium Suffers $1.34M Exploit as Attacker Drains Dormant Legacy AMM V3 Liquidity Pools on Solana

June 11, 2026
Next Post
Fortune Protocol Closes Seed Round to Expand AI Prediction Market Infrastructure

Fortune Protocol Closes Seed Round to Expand AI Prediction Market Infrastructure

Recommended

  • All
  • News
Coinbase Launches 11 Backed Tokenized Stocks and AI Investment Tools

Coinbase Launches 1:1 Backed Tokenized Stocks and AI Investment Tools

June 17, 2026
Ripple Invests in Flutterwave at $3.2 Billion Valuation to Expand Stablecoin Payments Across Africa

Ripple Invests in Flutterwave at $3.2 Billion Valuation to Expand Stablecoin Payments Across Africa

June 17, 2026
RetoSwap Suspends Trading Following Second Exploit in Haveno Protocol

RetoSwap Suspends Trading Following Second Exploit in Haveno Protocol

June 17, 2026
Binance Founder CZ Praises Hyperliquid but Says He Would Never Operate It the Same Way

Binance founder CZ Praises Hyperliquid but Says Binance Would Never Operate the Same Way

June 17, 2026
Coinbase Launches 11 Backed Tokenized Stocks and AI Investment Tools

Coinbase Launches 1:1 Backed Tokenized Stocks and AI Investment Tools

June 17, 2026
Ripple Invests in Flutterwave at $3.2 Billion Valuation to Expand Stablecoin Payments Across Africa

Ripple Invests in Flutterwave at $3.2 Billion Valuation to Expand Stablecoin Payments Across Africa

June 17, 2026
RetoSwap Suspends Trading Following Second Exploit in Haveno Protocol

RetoSwap Suspends Trading Following Second Exploit in Haveno Protocol

June 17, 2026
Binance Founder CZ Praises Hyperliquid but Says He Would Never Operate It the Same Way

Binance founder CZ Praises Hyperliquid but Says Binance Would Never Operate the Same Way

June 17, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Coinbase Launches 1:1 Backed Tokenized Stocks and AI Investment Tools
  • Ripple Invests in Flutterwave at $3.2 Billion Valuation to Expand Stablecoin Payments Across Africa
  • RetoSwap Suspends Trading Following Second Exploit in Haveno Protocol

Categories

  • AI × Crypto
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.