
Huma Finance suffered a significant security breach that drained approximately $101,400 from deprecated Polygon V1 BaseCreditPool contracts. According to reports from AMBCrypto and Blockaid, the attack exploited a flawed account validation logic inside the refreshAccount() function, which unconditionally promotes requested credit lines to 'GoodStanding' status without proper EA approval steps. The breach affected more than 82,315 USDC from one affected pool alone, while smaller USDC.e balances were drained from two additional contracts. As reported by Blockaid, the entire exploit was completed in a single transaction without any cryptographic issues, with the attacker simply changing the contract's state machine to trick it into treating unauthorized accounts as legitimate.
Despite the breach, Huma's newer Solana-based V2 infrastructure remained completely isolated from the compromised legacy deployments. As reported by AMBCrypto, Huma Finance co-founder Richard Liu described the exploit as a 'hard lesson' that should strengthen collective ecosystem defense. The team confirmed on X that "No user funds at risk and PST is not impacted" and emphasized that their V2 system, which runs on Solana, was built from scratch and shares no code with the compromised contracts. Huma had already been winding down V1 operations before the exploit occurred and has now fully paused all remaining V1 contracts.
The exploit highlighted the hidden maintenance burden growing beneath rapidly evolving DeFi infrastructure. According to AMBCrypto, as development resources concentrated on Huma's Solana V2 rewrite, older Polygon V1 modules gradually received less operational scrutiny despite remaining publicly accessible. Huma's newer Solana ecosystem already facilitated more than $13 billion in cumulative volume while maintaining roughly $179 million in active liquidity, contrasting sharply with the compromised legacy infrastructure. The incident reinforced how legacy infrastructure now represents one of DeFi's most persistent structural security risks.
The incident reinforces broader concerns around dormant smart contracts retaining residual approvals, treasury balances, and hidden attack surfaces. As reported by AMBCrypto, rising cross-chain complexity increasingly leaves older contracts under-audited and operationally exposed. The back-to-back exploits on Polygon come after April 2026, setting the record for the worst month of smart contract losses. In both incidents, attackers found logic mistakes in smart contract design, with Ink Finance also losing almost $140,000 from its Workspace Treasury Proxy contract on Polygon the same day. Huma's accelerated V1 shutdown ultimately reinforced how protocols increasingly prioritize disciplined infrastructure retirement over rapid growth.