← Radar

Incident case file

Sign in to watch

Hinkal Protocol — Proofless Deposit Exploit — Contracts Paused, Full Reimbursement Pledged

Incident date July 2, 2026

1 views

PausedEthereumZero-knowledge protocol logic flaw / proofless deposit exploitCluster: HINKAL-PROOFLESS-2026-07

Estimated loss

$797K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Attacker: 0xbB3f01a1b1C68F3DEB36C55342b5F5706c32fc20

Funds moved to: Attacker withdrew approximately 797,000 USDC from a single Hinkal contract on Ethereum (official Hinkal figure, superseding earlier CertiK estimate of ~$800K), converted it to roughly 454 ETH. Of that, 410 ETH was deposited into Tornado Cash (confirmed via Etherscan: multiple 10 ETH and 100 ETH batch deposits over ~40 minutes) and 44.6747 ETH was bridged to Bitcoin via THORChain (Ethereum-side deposit tx: 0x14dd7a300b..., method 'Deposit With...'). Final Bitcoin-side receiving address not yet id
Funding pre-attack: the attacker address received gas from 0x105ad144e8952236144dfe2e135ced7812e3d7c0 (2026-07-03, 05:49:47 UTC), which was itself funded further upstream by Binance 18 (oldest traced source, per Bubblemaps fund-flow analysis) — this funding chain is consistent with routine gas provisioning and is not itself evidence of exchange-level KYC compromise. The incident was isolated to a single smart contract pool on Ethereum; Hinkal deployments on Arbitrum, Base, and Polygon/OP Mainn

Timeline: T0 (2026-07-02, 19:05 UTC): Attacker begins withdrawing approximately 797,000 USDC from a Hinkal contract on Ethereum via a series of 'Transact' calls, each exploiting a 'Proofless Deposit' — submitting fresh nullifier/stealth/H0/H1/calldataHash values without a corresponding valid prior deposit, per CertiK's technical analysis: 'this suggests failure of the signature scheme implementation to bind commitment and nullifier.' In each call, roughly $25K was withdrawn. T+hours (2026-07-03, 04:35 UTC): CertiK Alert publishes the first public detection, describing the EOA as having conducted multiple 'Transact' transactions following a 'Proofless Deposit' to drain ~$800K USDC from a Hinkal contract. T+shortly after: CertiK confirms the attacker swapped the drained USDC to ETH, depositing 410 ETH into Tornado Cash while bridging 44.67 ETH to BTC via THORChain. T+same day: the affected contracts are frozen as a precautionary measure (confirmed via Hinkal's official account). T+2026-07-03, 14:47 UTC: Hinkal Protocol posts an official update confirming the incident was isolated to USDC on Ethereum, no other chains affected, contracts paused pending investigation. T+2026-07-03, 23:05 UTC: Hinkal posts a detailed follow-up confirming the exact figures — ~797K USDC withdrawn starting 2026-07-02 19:05 UTC, converted to ~454 ETH, 410 ETH to Tornado Cash, 44.67 ETH bridged to Bitcoin via THORChain — and pledges that no user will lose funds, with all affected balances to be made whole 1:1 once the reimbursement process and fix are finalized. The incident has been reported to relevant US authorities. Status as of report compilation: contracts remain paused across all chains, root cause validated internally and with external security specialists, full technical breakdown and reimbursement plan still pending publication.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)