ChainBleedv0.1 · open intel
← back to feed·SOLLOGIC2026-05-11 · 29d ago
Incident · SLOWMIST

Huma Finance

Contract Vulnerability
Estimated loss
$101.4K
VERDICT —UNRATED
Verdict pending. Auto-ingested incidents are reviewed before a public verdict is rendered.
▰ METHOD
LOGIC
LOGICBYTECODE CATCHABLEAI SCANNABLE
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

Forensic narrative

A logic flaw in Huma Finance’s deprecated V1 BaseCreditPool contracts on Polygon was exploited, draining approximately 101,400 USDC and USDC.e from accumulated protocol fees and pool owner fees. No user funds were at risk, PST token unaffected. The team had already been sunsetting V1 pools and immediately paused all V1 contracts. Huma’s V2 on Solana is a complete rewrite and remains secure. Attack method (per SlowMist): Contract Vulnerability. Reported loss: $ 101,400.

Primary source
https://x.com/humafinance/status/2053858499378258198
Sourced from
slowmist
Technical record
chain
solana
protocol
Huma Finance
bug_class
logic
date_occurred
2026-05-11
loss_usd
$101,400
source_id
sm:huma-finance::2026-05-11
Related — same bug class· logic
2026-05-13
27d ago
TRON
Transit Finance
Deprecated Smart Contract Exploit
logic
$1.88M
UNRATED
2026-05-13
27d ago
ETH
TAC Cross-Chain Layer (TON Side)
Contract Vulnerability
logic
$2.80M
UNRATED
2026-05-13
27d ago
ETH
Transit Finance
Contract Vulnerability
logic
$1.88M
UNRATED
2026-05-12
28d ago
ARB
Aurellion
Uninitialized Proxy Exploit
logic
$456.0K
UNRATED
2026-05-12
28d ago
BSC
SQ Protocol
Acces Control Exploit
logic
$346.0K
UNRATED
2026-05-12
28d ago
BSC
SQ Protocol
Contract Vulnerability
logic
$346.1K
UNRATED
ChainBleed — live web3 threat intelligence