ChainBleedv0.1 · open intel
← back to feed·POLYFLASHLOAN2026-05-11 · 29d ago
Incident · SLOWMIST

Ink Finance

Contract Vulnerability
Estimated loss
$140.0K
VERDICT —UNRATED
Verdict pending. Auto-ingested incidents are reviewed before a public verdict is rendered.
▰ METHOD
FLASHLOAN
FLASHLOANBYTECODE CATCHABLEAI SCANNABLE
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

Forensic narrative

Ink Finance’s Workspace Treasury Proxy contract on Polygon was exploited due to a whitelist validation logic flaw. The attacker deployed a malicious contract matching a whitelisted claimer address, passed authentication checks via the claim() function, and drained approximately $140,000 USDT (amplified with a ~$25K Balancer V2 flash loan). Attack method (per SlowMist): Contract Vulnerability. Reported loss: $ 140,000.

Primary source
https://www.cryptotimes.io/2026/05/11/ink-finance-exploited-on-polygon-140k-usdt-drained-in-flash-loan-attack/
Sourced from
slowmist
Technical record
chain
polygon
protocol
Ink Finance
bug_class
flashloan
date_occurred
2026-05-11
loss_usd
$140,000
source_id
sm:ink-finance::2026-05-11
Related — same bug class· flashloan
2026-05-04
1mo ago
ETH
SmartCredit
Flashloan Exploit
flashloan
$72.0K
UNRATED
2026-05-04
1mo ago
SmartCredit
Flash Loan Exploit
flashloan
$72.0K
UNRATED
2026-04-28
1mo ago
BSC
JUDAO
Flashloan Exploit
flashloan
$228.0K
UNRATED
2026-04-28
1mo ago
JUDAO
Exploit
flashloan
$228.0K
UNRATED
2026-04-15
1mo ago
LootBot AI
Contract Vulnerability
flashloan
$9.6K
UNRATED
2026-04-14
1mo ago
BSC
MONA
Deferred LP Burn Exploit
flashloan
$61.0K
UNRATED
ChainBleed — live web3 threat intelligence