Hinkal Protocol breach: $820K stolen, laundered via mixers
Hinkal Protocol lost about $820,000 in USDC to an exploit. Funds were laundered via Tornado Cash and THORChain. Hinkal froze contracts and is investigating, with updates promised.
Hinkal Protocol, a privacy-focused DeFi platform, suffered a major security breach resulting in the loss of approximately $820,000 to $822,000 in USDC. The attacker exploited a vulnerability, reportedly in the protocol’s prooflessDeposit() function, executing multiple transactions to siphon funds. The stolen assets were quickly laundered: around $700,000 was swapped for Ethereum and sent to Tornado Cash, while another portion was transferred to Bitcoin via THORChain. The incident was first flagged by on-chain investigator Specter and later confirmed by security firms including CertiK, PeckShield, and GoPlus Security. In response, Hinkal froze the affected smart contracts and launched a thorough investigation, noting the issue appears limited to the Ethereum blockchain. The team has promised further updates after completing their analysis. This exploit underscores ongoing concerns about DeFi security and the challenges of tracing laundered funds.