Huma Finance Legacy V1 Contract on Polygon Breached, Resulting in $101,400 Theft in USDC
A logic flaw in Huma’s outdated V1 Polygon credit pools enabled an attacker to withdraw around $101,400 in USDC. However, Huma’s Solana-based PayFi V2 and PST token continue to function properly.
Summary
- Huma disclosed that the outdated V1 BaseCreditPool contracts on Polygon were exploited for approximately $101,400 in USDC and USDC.e during the winding down phase, while the current PayFi V2 on Solana remained unaffected.
- Blockaid attributed the loss to a flaw in the refreshAccount() logic that mistakenly designated borrowers as “GoodStanding” without proper checks, allowing the attacker to withdraw from treasury-linked pools in a single scripted transaction.
- All remaining V1 contracts on Polygon have since been paused, with Huma confirming that ongoing deposits and PST holdings on Solana’s updated, permissionless PayFi platform are separate from the vulnerable V1 contracts.
Huma Finance revealed that its outdated V1 contracts on Polygon were compromised, resulting in a loss of around $101,400 in USDC and USDC.e from previous liquidity pools that were being retired. The team stressed that user deposits on its current PayFi platform are secure, and Huma’s PST token remains unaffected, with the newly designed V2 system on Solana distinctly separate from the compromised V1 contracts.
An official announcement on X noted, “Huma Finance’s V1 BaseCreditPool deployments on Polygon were compromised … totaling ~$101K. Total drained: ~$101.4K (USDC + USDC.e),” confirming the incident was confined to deprecated contracts rather than active production vaults. A detailed assessment by the Web3 security firm Blockaid, referenced by CryptoTimes, identified the loss as stemming from a logic error in a function named refreshAccount() within the V1 BaseCreditPool contracts, which inappropriately changed an account’s status from “Requested credit line” to “GoodStanding” without sufficient validation.
This flaw allowed the attacker to bypass access controls and withdraw funds from treasury-linked pools as if they were authorized borrowers. Blockaid’s investigation found that approximately 82,315.57 USDC was drained from one contract (0x3EBc1), 17,290.76 USDC.e from another (0x95533), and 1,783.97 USDC.e from a third (0xe8926), all in a single, coordinated transaction. The exploit did not involve breaking encryption or private keys but rather manipulating business logic to mislead the system into allowing the attacker to withdraw funds.
Huma acknowledged that it was in the process of decommissioning its V1 liquidity pools on Polygon when the exploit occurred and has since completely halted all remaining V1 contracts to prevent further risk. In its statement, the team highlighted that Huma 2.0 — a permissionless, composable “real-yield” PayFi platform launched on Solana in April 2025 with support from Circle and the Solana Foundation — represents “a complete rebuild” with a different architecture, distinct from the compromised V1 code.
The Huma 2.0 design focuses on the $PST (PayFi Strategy Token), a liquid, yield-bearing LP token that represents positions in payment-financing strategies and can be integrated with Solana DeFi protocols like Jupiter, Kamino, and RateX. In contrast, the compromised V1 contracts were part of an older, permissioned credit-pool framework on Polygon, which is now effectively retired.
The key takeaway for users is that the approximate $101,400 loss impacted legacy protocol-level liquidity rather than individual wallets, and that ongoing deposits and PST holdings on Solana are reported to be secure. Nevertheless, this incident adds to a growing list of DeFi exploits where vulnerabilities arose not from cryptographic failures, but from flawed business logic in outdated contracts — highlighting the need for teams like Huma to evolve to new architectures, and for users to treat “legacy” and “soon-to-be-deprecated” pools with the same caution they apply to unaudited code.
