Incident case file
Sign in to watchHuma Finance V1 — Deprecated BaseCreditPool Logic Exploit
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: TODO — flagged only via Blockaid tweet, no public EOA published
Timeline: On May 11, 2026 around 15:10 UTC, Blockaid flagged an exploit targeting Huma Finance's deprecated V1 BaseCreditPool contracts on Polygon. The vulnerability was in the refreshAccount() function, which wrongly upgraded an account's status from 'Requested credit line' to 'GoodStanding' without proper validation. The attacker exploited this to bypass access control and drain protocol fees from three V1 contracts: 0x3EBc1... (82,315.57 USDC), 0x95533... (17,290.76 USDC.e), and 0xe8926... (1,783.97 USDC.e). Critically, no user deposits were at risk — the drain was limited to protocol fee accounts and pool owner fees. Huma confirmed that the V2 protocol on Solana is a complete rewrite and was not affected, and that the PST token was not impacted. The V1 contracts were officially deprecated but had remained on-chain.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)