Huma Finance Legacy V1 Hack

Reported loss $101K
Polygon
Improper Access Control

What happened

On May 11, 2026, deprecated Huma Finance V1 BaseCreditPool contracts on Polygon were exploited for approximately $101,400 in USDC and USDC.e. Huma said the live V2 system on Solana, PST, and user deposits were not affected, and the legacy pools were paused.

Technical root cause

The legacy BaseCreditPool state machine allowed refreshAccount and its due-info path to promote a Requested credit line to GoodStanding without an Evaluation Agent approval, bypassing the authorization precondition checked by drawdown.

How it happened

The attacker requested credit without Evaluation Agent approval, called refreshAccount to move the credit record into GoodStanding, and then used drawdown to withdraw the balances of three legacy pools.

Protocol details

Classification Access Control
Protocol Type DeFi Protocol
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.