SciPHRSciPHR/ Learn sciphr.io ↗

Hinkal's proofless deposit exploit.

2026-07-03

On July 3, an attacker drained about $820,000 in USDC from Hinkal, an on-chain privacy protocol, taking nearly everything the pool held.

Hinkal lets people move funds on a public blockchain without revealing balances or counterparties. To do that, a deposit is recorded as a hidden balance, and a cryptographic proof stands in for the receipt showing the money was actually put in. A later withdrawal checks that proof before releasing funds.

Think of a coat check that returns a coat only when your ticket matches one you checked in. The attacker got a ticket for a coat never checked in, making a deposit the contract accepted without a valid proof, then withdrawing against a balance the pool never received.

The signatures were valid and the chain did as instructed. What failed was the contract trusting a claim it never verified.

Source: https://www.cryptopolitan.com/hinkal-privacy-protocol-exploited-for-820000-as-attacker-funnels-stolen-funds-through-tornado-cash/

← BackAll of Learn
Network: TESTNET ·_