Logic flaw drains $101K from Huma’s old Polygon contracts
A logic flaw in Huma Finance’s legacy V1 smart contracts on Polygon enabled an attacker to drain $101,400 in stablecoins in a single transaction, highlighting how abandoned infrastructure remains a persistent attack surface even after teams shift focus to newer systems. The incident underscores a structural risk for institutional investors: legacy DeFi contracts often linger in production long after development resources move elsewhere, creating maintenance blind spots that malicious actors systematically exploit.
- Attacker drained $101,400 USDC across three BaseCreditPool contracts in one transaction on Polygon.
- Bug in refreshAccount() function bypassed approval requirements by falsely marking unauthorized accounts as good standing.
- Huma had already begun sunsetting V1 when exploited; V2 on Solana completely unaffected and operating normally.
- $101,400 total USDC lost across V1 contracts on Polygon network.
- 1 transaction needed to drain funds from three separate contract deployments.
- May 11, 2026 date Huma exploit occurred, same day as Ink Finance $140K incident on Polygon.
A vulnerability buried deep in Huma Finance’s legacy V1 smart contracts allowed an attacker to siphon $101,400 in stablecoins from the protocol’s treasury pools on Polygon in a single transaction on May 11, 2026. Security firm Blockaid identified the flaw within the refreshAccount() function in BaseCreditPool contracts, a function responsible for updating account status within the lending system.
Rather than verify eligibility through proper channels, the function unconditionally promoted credit lines to “good standing” status, bypassing the approval step required to unlock fund withdrawals. The attacker exploited this state-machine logic error to impersonate an authorized account and execute drawdown operations against unprotected pools.
The breach affected three separate contract instances, with individual losses of approximately $82,300 USDC, $17,300 USDC.e, and $1,800 USDC.e respectively. Huma confirmed the incident on X, stating that no user deposits held in its newer V2 system on Solana were at risk and that the production platform continues normal operations.
The company emphasized that V2 was built from scratch with entirely different code architecture, isolating the vulnerability to obsolete infrastructure.
refreshAccount() Function Lacked Conditional Checks Required for Credit Line Promotion
The core vulnerability stemmed from poor access control design in a single contract function. Blockaid’s technical analysis revealed that refreshAccount() performed a critical state transition, promoting a credit line from “Requested” status to “GoodStanding” status, without requiring approval from any external authority or executing conditional validation logic.
In properly architected lending systems, such transitions require sign-off from designated roles (often labeled “Eligibility Agents” or similar) and verification that the account meets predefined criteria.
By removing those gatekeeping steps, Huma’s V1 code treated the refreshAccount() function as a direct pathway from request to approval. An attacker with the ability to call this function could manufacture legitimate-appearing account states and immediately begin withdrawing collateralized assets.
The exploit executed in a single on-chain transaction, suggesting no additional complexity, no flash loan mechanics, no price manipulation, no cryptographic compromise. The attacker simply invoked state changes that the contract was never supposed to permit unilaterally.
This type of logic error, where developers omit necessary access controls or conditional checks, has become one of the most common vectors for DeFi contract exploits over the past three years.
The flaw indicates that V1 underwent insufficient peer review or formal verification before deployment, a limitation that likely reflected the earlier, faster-moving development cycle of 2023-2024 DeFi infrastructure.
Huma’s Planned Sunset of V1 Already Underway Before Exploit Surfaced
The timing of the exploit is significant: Huma’s team had already initiated the deprecation of V1 when the attack occurred. According to the company’s public statement, the team was actively winding down V1 pool operations and had begun transitioning users to V2 infrastructure on Solana.
The exploit accelerated this timeline by forcing an immediate full pause of all remaining V1 contracts to prevent further drainage.
This context matters for institutional risk assessment. A protocol abandoning legacy code typically signals either that new architecture has proven superior or that maintenance costs no longer justify continued operation. However, the lag between development team shift and complete contract retirement creates a window of vulnerability.
During that window, fewer developers monitor transactions, fewer security audits occur, and fewer infrastructure upgrades happen, precisely when legacy contracts become most attractive to attackers aware they will eventually disappear.
Huma’s move to Solana with V2 represents a full rewrite rather than an incremental update, meaning no code was carried forward and no shared vulnerabilities exist between the compromised contracts and the current product. User deposits on V2 remained unaffected and the newer platform continued processing transactions normally throughout the incident.
Polygon Network Faces Repeated Logic Vulnerabilities on the Same Day
The Huma exploit arrived on a particularly vulnerable day for Polygon-based protocols. On May 11, 2026, Ink Finance separately suffered a loss of nearly $140,000 from its Workspace Treasury Proxy contract when attackers deployed a contract matching a whitelisted claimer address to bypass eligibility verification.
Both incidents involved attackers finding and exploiting logic flaws rather than cryptographic weaknesses, revealing a pattern of insufficient access control and state validation across multiple protocols on the network.
For institutional investors allocating to Polygon-based DeFi, these twin exploits surface a broader operational risk: many protocols running on Polygon maintain legacy contracts longer than intended, and some lack sufficient incentive structures to fund ongoing security monitoring once development teams shift focus.
Polygon’s architecture itself was not compromised, both attacks succeeded through application-layer logic errors rather than network-level vulnerabilities, but the concentration of similar flaws in the same timeframe suggests inadequate security maturity across parts of the ecosystem.
The incidents also highlight the value of post-mortem transparency. Blockaid’s detailed public analysis of the refreshAccount() flaw and the three affected contract addresses enables other protocols to audit their own code for similar patterns, potentially preventing copycat exploits elsewhere.
The key institutional takeaway centers on the operational and security risks of legacy contract retirement: Huma’s team must now monitor whether attackers make further attempts against remaining V1 pools despite the pause, and whether other Polygon protocols will accelerate security audits of deprecated infrastructure before sunsetting it completely. Investors should track whether Huma publishes a formal post-mortem documenting the code review process that allowed refreshAccount() to reach production without proper access controls, and whether the company implements additional safeguards during V2’s ongoing operation on Solana, such as formal verification or multi-signature requirements for critical state transitions, to prevent similar lapses in the next generation.
Original reporting: cryptopolitan.com