← Radar

Incident case file

Sign in to watch

Huma Finance V1 — Deprecated BaseCreditPool Logic Exploit

Incident date May 11, 2026

0 views

ResolvedPolygonDeprecated contract / Logic exploitCluster: HUMA-POLY-2026-05

Estimated loss

$101.4K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

85%

Facts and investigation

Attacker: TODO — flagged only via Blockaid tweet, no public EOA published

Funds moved to: TODO — drained from protocol fee accounts only; no public laundering trace
No attacker EOA publicly disclosed (Blockaid alert reference: x.com/humafinance/status/2053858499378258198). Three deprecated V1 BaseCreditPool contracts were drained: 0x3EBc1... (82,315.57 USDC), 0x95533... (17,290.76 USDC.e), 0xe8926... (1,783.97 USDC.e). The vulnerable function refreshAccount() upgraded account status from 'Requested credit line' to 'GoodStanding' without proper validation, bypassing the access control needed to withdraw protocol fees. No user deposits were at risk — drain li

Timeline: On May 11, 2026 around 15:10 UTC, Blockaid flagged an exploit targeting Huma Finance's deprecated V1 BaseCreditPool contracts on Polygon. The vulnerability was in the refreshAccount() function, which wrongly upgraded an account's status from 'Requested credit line' to 'GoodStanding' without proper validation. The attacker exploited this to bypass access control and drain protocol fees from three V1 contracts: 0x3EBc1... (82,315.57 USDC), 0x95533... (17,290.76 USDC.e), and 0xe8926... (1,783.97 USDC.e). Critically, no user deposits were at risk — the drain was limited to protocol fee accounts and pool owner fees. Huma confirmed that the V2 protocol on Solana is a complete rewrite and was not affected, and that the PST token was not impacted. The V1 contracts were officially deprecated but had remained on-chain.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)