Hinkal has frozen affected smart contracts after reports of unusual on-chain activity involving USDC on Ethereum and other supported networks, as the privacy-focused protocol investigates a suspected exploit.
The team said it took the precautionary step of freezing the affected contracts while engineers review the incident and analyze on-chain transactions. Hinkal added that the investigation is ongoing and that verified updates will be shared once more information becomes available.
We are aware of reports regarding unusual activity involving USDC on Ethereum and other chains within Hinkal.
As a precautionary measure, the affected contracts have been frozen while our engineering team investigates and analyzes the on-chain activity in full.
The…
— hinkal (@hinkal_protocol) July 3, 2026
Blockchain security firm GoPlus Security said the attacker allegedly exploited Hinkal’s prooflessDeposit() function and carried out multiple transactions to drain approximately $820,000 in USDC from the protocol. The firm identified the suspected attacker and the affected Hinkal contract, and shared the relevant on-chain transactions as part of its preliminary findings.
Investigation focuses on contract behaviour
Hinkal has not confirmed the cause of the incident or the total amount of funds affected, saying only that the investigation remains underway.
GoPlus Security said the exploit appears to involve the protocol’s deposit mechanism, allowing the attacker to remove USDC through repeated transactions. The security firm published the suspected contract address, attacker wallet, and example Ethereum transactions as part of its findings.
The protocol has not announced when the frozen contracts will be reopened or whether users will need to take any action while the review continues.
RELATED: Bunni Shuts Down After $8.4 Million Exploit, Marking Another Major Setback for DeFi Security
Why is privacy no longer enough?
Privacy alone is no longer enough because users, businesses, and regulators now expect security and accountability alongside confidentiality. Modern privacy protocols are increasingly using technologies such as zero-knowledge proofs to let users verify ownership, balances, or compliance without exposing sensitive information. As these systems become more advanced, protecting user data is only part of the challenge, ensuring the underlying technology is secure has become just as important.
That move has increased as regulators have tightened oversight following sanctions on privacy services such as Tornado Cash and increased scrutiny of anonymous crypto transactions. Rather than focusing only on hiding activity, newer privacy projects are trying to balance confidentiality with the ability to verify transactions when necessary.
The result is that security has become just as important as privacy. Every new cryptographic feature or privacy layer adds another piece of code that must be tested and audited.
Enjoyed this? Bookmark DeFi Planet, explore related topics, and follow us on Twitter, LinkedIn, Facebook, Instagram, Threads, and CoinMarketCap Community for seamless access to high-quality industry insights
Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.
























































































