Incident case file
Sign in to watchINK Finance — Whitelist Bypass + Balancer V2 Flash Loan Exploit
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0x90b147592191388e955401af43842e19faa87ee2
Timeline: On May 11, 2026 around 13:41 UTC, Blockaid detected an exploit against INK Finance's Workspace Treasury Proxy on Polygon. The attacker deployed a malicious contract whose address matched a whitelisted claimer address on the unverified EIP-1967 beacon proxy (0xa184Af4B1c01815A4B57422A3419E4FB78a96Ee4). By passing authentication via claim(), the attacker bypassed eligibility checks. To satisfy a balance condition required by the contract logic, they borrowed approximately $25K from Balancer V2 as a flash loan, drained ~$140K USDT from the treasury proxy, and repaid the flash loan within the same atomic transaction. The attacker EOA 0x90b147592191388e955401af43842e19faa87ee2 had been pre-funded via Railgun on Ethereum and bridged to Polygon approximately 32 minutes before the exploit. The unverified status of the proxy contract on Polygonscan complicated public forensics.
Sources and coverage
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/05/11/ink-finance-exploited-on-polygon-140k-usdt-drained-in-flash-loan-attack/
- Articlecryip.cohttps://cryip.co/ink-finance-suffers-140k-drain-on-polygon-attacker-exploits-treasury-proxy-via-whitelist-flaw-and-flash-loan/
- Articleambcrypto.comhttps://ambcrypto.com/ink-finance-loses-140k-as-whitelist-bypass-exploit-targets-treasury-infrastructure-details/
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)