Hinkal's proofless deposit exploit.
On July 3, an attacker drained about $820,000 in USDC from Hinkal, an on-chain privacy protocol, taking nearly everything the pool held.
Hinkal lets people move funds on a public blockchain without revealing balances or counterparties. To do that, a deposit is recorded as a hidden balance, and a cryptographic proof stands in for the receipt showing the money was actually put in. A later withdrawal checks that proof before releasing funds.
Think of a coat check that returns a coat only when your ticket matches one you checked in. The attacker got a ticket for a coat never checked in, making a deposit the contract accepted without a valid proof, then withdrawing against a balance the pool never received.
The signatures were valid and the chain did as instructed. What failed was the contract trusting a claim it never verified.
Related
SciPHR