← Radar

Incident case file

Sign in to watch

INK Finance — Whitelist Bypass + Balancer V2 Flash Loan Exploit

Incident date May 11, 2026

0 views

UnknownPolygonWhitelist bypass / Flash loan exploitCluster: INK-POLY-2026-05

Estimated loss

$140K

Victims identified

1
Victim group joining is coming soon.

Investigation

70%

Facts and investigation

Attacker: 0x90b147592191388e955401af43842e19faa87ee2

Funds moved to: TODO — ~$140K USDT; no public downstream laundering trace as of May 16
Attacker EOA: 0x90b147592191388e955401af43842e19faa87ee2. Victim Workspace Treasury Proxy: 0xa184Af4B1c01815A4B57422A3419E4FB78a96Ee4 (EIP-1967 beacon proxy, deployed Dec 2023, unverified on Polygonscan at exploit time). Implementation contract: 0x72225ccb...7AFc89890. Attacker pre-funded via Railgun on Ethereum, then bridged to Polygon approximately 32 minutes before the exploit. Flash loan capital: ~$25K borrowed from Balancer V2.

Timeline: On May 11, 2026 around 13:41 UTC, Blockaid detected an exploit against INK Finance's Workspace Treasury Proxy on Polygon. The attacker deployed a malicious contract whose address matched a whitelisted claimer address on the unverified EIP-1967 beacon proxy (0xa184Af4B1c01815A4B57422A3419E4FB78a96Ee4). By passing authentication via claim(), the attacker bypassed eligibility checks. To satisfy a balance condition required by the contract logic, they borrowed approximately $25K from Balancer V2 as a flash loan, drained ~$140K USDT from the treasury proxy, and repaid the flash loan within the same atomic transaction. The attacker EOA 0x90b147592191388e955401af43842e19faa87ee2 had been pre-funded via Railgun on Ethereum and bridged to Polygon approximately 32 minutes before the exploit. The unverified status of the proxy contract on Polygonscan complicated public forensics.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)