Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
No Result
View All Result
Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
No Result
View All Result
Cryip
No Result
View All Result
Home Crypto News Today Security & Hacks

INK Finance Suffers $140K Drain on Polygon: Attacker Exploits Treasury Proxy via Whitelist Flaw and Flash Loan

Attackers exploited a weakness in INK Finance’s treasury proxy validation system, using a flash loan to siphon nearly $140,000 USDT in a single Polygon transaction.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
May 11, 2026
in Security & Hacks
0 0
INK Finance Suffers $140K

Created By Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

Decentralized finance never sleeps, and even platforms designed for secure treasury management can sometimes get caught off guard. On May 11, 2026, INK Finance became the latest project to suffer a security breach when an attacker drained roughly $140,000 in USDT from its Workspace Treasury Proxy contract on the Polygon network. Security firm Blockaid was the first to flag the incident.
What makes this exploit stand out is its clean and methodical execution rather than the size of the haul. The attacker didn’t steal private keys or tamper with oracles. Instead, they took advantage of a flaw in the whitelist validation and smartly combined it with a flash loan to drain the funds in a single transaction.

🚨 Community Alert@inkfinance‘s Workspace Treasury Proxy on Polygon was exploited a few minutes ago for ~$140K.

More details in🧵

— Blockaid (@blockaid_) May 11, 2026

What is INK Finance?

INK Finance is a multichain platform designed to serve as a financial operating system for DAOs, protocols, and Real World Asset projects. It provides tools for on-chain treasury management, governance, payments, fundraising, and compliance.

The platform allows teams to create customizable “workspaces” with different committees for treasury, investments, and community decisions. Its core offering includes the Universal Custodian Vault and Workspace Treasury Proxy, which many DAOs use to handle authorized transfers efficiently. The project is mainly active on Polygon and Avalanche.

The compromised contract (0xa184…96Ee4), an EIP-1967 beacon proxy deployed in late 2023, was the target of today’s attack.

How the Exploit Happened

According to initial findings from Blockaid and other security researchers, the attacker executed a precise and well-planned attack by following these key steps in a single atomic transaction:

  • Deployed a Malicious Contract: The attacker first created and deployed a malicious smart contract that was carefully designed to satisfy the whitelist criteria in INK Finance’s Workspace controller. This allowed the contract to appear as a legitimate, pre-approved claimer.
  • Triggered the Claim Function: Using this malicious contract, the attacker then called the claim(claimId) function on the controller. Because the whitelist check was passed successfully, the request moved forward and triggered an authorized withdrawal from the Workspace Treasury Proxy without raising any red flags.
  • Used a Flash Loan for Amplification: To meet any required balance or collateral conditions inside the claim process, the attacker borrowed approximately $25,000 through a Balancer V2 flash loan within the same transaction. This temporary capital boost enabled the full drainage of around $140,000 in USDT. Once the funds were extracted, the flash loan was automatically repaid before the transaction concluded.

The full exploit transaction can be viewed on Polygonscan: 0xb469…6b982

Attacker address: 0x90b1…87ee2

Funding Trail

On-chain data shows the attacker received funds through Railgun on Ethereum for privacy before bridging to Polygon just 32 minutes before executing the exploit. This suggests the attack was carefully prepared in advance.

Current Situation and Advice for Users

INK Finance has acknowledged the incident, though a complete technical post-mortem and recovery plan have not yet been released.

Users and DAOs with active workspaces on Polygon or Avalanche are strongly advised to:

  • Immediately revoke approvals tied to affected controller and proxy contracts.
  • Audit all whitelisted claimer addresses and permissions.
  • Monitor official INK Finance announcements before moving treasury assets.
  • Increase monitoring for unusual proxy interactions or sudden treasury withdrawals.

Broader Implications

While a $140K loss is relatively small compared to some of the larger DeFi hacks seen in 2026, this incident once again highlights a persistent weakness across decentralized finance: flawed authorization logic inside treasury systems.

Whitelist-based mechanisms remain convenient for DAO operations, but they can become dangerous when protocols fail to re-validate transaction amounts, ownership, or destination addresses during execution. Similar vulnerabilities have also surfaced in other protocols, including the Aftermath Finance exploit, where attackers reportedly drained more than $1.14 million through weaknesses tied to smart contract execution logic.

The INK Finance incident serves as another reminder that security in DeFi is not a one-time checklist. Continuous audits, layered permission controls, real-time monitoring, and stricter validation mechanisms are becoming essential for protecting on-chain treasury infrastructure.

As the DeFi ecosystem matures, both builders and users will need to remain proactive and vigilant against increasingly sophisticated exploit strategies.

AI Disclosure: Cryip uses AI-assisted tools to help refine language — correcting spelling and grammar and simplifying complex terms for readability.

We do this to make crypto topics easier to understand for readers at all experience levels. AI does not draft facts, sources, or conclusions. Every article is reviewed and approved by a human editor before publication. Read our full AI Use & Content Policy.

Disclaimer: Cryip’s content is strictly for informational purposes and does not constitute financial, legal, or investment advice. Asset references are not endorsements, and readers assume full responsibility for any financial decisions.
Tags: Crypto HacksPolygon
Saravana Kumar Mahendran

Saravana Kumar Mahendran

Saravana Kumar Mahendran is a crypto security analyst and blockchain researcher at Cryip, focusing on DeFi protocol exploits, Web3 security systems, and on-chain investigation. His research applies OSINT and fact-checking methodology to security incidents, drawing on certifications in cybersecurity and data analytics (LinkedIn Learning), and DeFi deep-dive training (Binance Academy). His work has been cited by Sherlock, Rekt.news, and Halborn Security.

Related Posts

Bybit’s Own Filings Show Recovery Barely Moved in 7 Weeks After Suing North Korea
Security & Hacks

Bybit’s Own Filings Show Recovery Barely Moved in 7 Weeks After Suing North Korea

by Saravana Kumar Mahendran
August 8, 2026

Bybit's June 2026 complaint says about $75.5 million (5.3%) of the $1.5 billion stolen in February 2025 had been frozen...

Read moreDetails
Coldcard Hack Losses Nearly $100 Million

Coldcard Hack Losses Nearly $100 Million as Root Cause Reveals a Wider Flaw

August 4, 2026
Boltz Disables Bitcoin Swaps Indefinitely After Monthslong AI-Assisted Attacks

Boltz Disables Bitcoin Swaps Indefinitely After Months long AI-Assisted Attacks

August 4, 2026
BitGo’s Belshe Dares Anthropic to Hack His Bitcoin Wallet, Again

BitGo’s Belshe Dares Anthropic to Hack His Bitcoin Wallet, Again

August 3, 2026
July 2026 Crypto Hacks: Nearly $200M Lost Across Wallets, DeFi and Bridges

July 2026 Crypto Hacks: Nearly $200M Lost Across Wallets, DeFi and Bridges

August 1, 2026
Coldcard Advisory Ties 594 BTC Theft to a Flaw Found Only in Mk3

Coldcard Advisory Ties 594 BTC Theft to a Flaw Found Only in Mk3

July 31, 2026
Drift Protocol Hacker Moves $44M in ETH to Tornado Cash After Three Months

Drift Exploiter Moves $44M in ETH Through Tornado Cash After Three Months of Inactivity

July 24, 2026
Next Post
Fortune Protocol Closes Seed Round to Expand AI Prediction Market Infrastructure

Fortune Protocol Closes Seed Round to Expand AI Prediction Market Infrastructure

MoonPay Acquires Dawn Labs to Expand AI Trading Infrastructure Strategy

MoonPay Acquires Dawn Labs to Expand AI Trading Infrastructure Strategy

Recommended

  • All
  • Crypto News Today
Saylor Says Bitcoin BIP-110 Lacks Miner Consensus at 2.6% Support

Saylor Says Bitcoin BIP-110 Lacks Miner Consensus at 2.6% Support

August 8, 2026
Treasury Sanctions Shelbit, Aban Tether: Dubai’s Own Fine Changed Nothing

Treasury Sanctions Shelbit, Aban Tether: Dubai’s Own Fine Changed Nothing

August 8, 2026
Trump Media Ends Crypto.com Partnership, Signaling Retreat From Its Crypto Expansion Plans

Trump Media Ends Crypto.com Partnership, Signaling Retreat From Its Crypto Expansion Plans

August 8, 2026
Bybit’s Own Filings Show Recovery Barely Moved in 7 Weeks After Suing North Korea

Bybit’s Own Filings Show Recovery Barely Moved in 7 Weeks After Suing North Korea

August 8, 2026
Brazil Tightens Crypto Transfer Rules With 24-Hour Delay to Combat Fraud

Brazil Tightens Crypto Transfer Rules With 24-Hour Delay to Combat Fraud

August 8, 2026
oung people from the Russian regions looking for easy money

FSB Shuts Down Nine Illegal Moscow Crypto Exchanges Linked to Ukrainian Call-Center Fraud

August 8, 2026
MetaMask's New AI Wallet Caps Loss Protection at $10,000 a Month

MetaMask’s New AI Wallet Caps Loss Protection at $10,000 a Month

August 8, 2026
Why BONK Is Being Delisted From Upbit: A $20M Hack and a Two-Month Review

Why BONK Is Being Delisted From Upbit: A $20M Hack and a Two-Month Review

August 7, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • South Africa’s Rand Stablecoin Lost to Dollar Tokens: Now the IMF Says That’s a Warning Sign
  • Saylor Says Bitcoin BIP-110 Lacks Miner Consensus at 2.6% Support
  • Treasury Sanctions Shelbit, Aban Tether: Dubai’s Own Fine Changed Nothing

Categories

  • AI × Crypto
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.