Hinkal, a privacy-focused DeFi protocol, has suffered an exploit worth nearly $820,000. The incident was first flagged by CertiK, surfaced publicly through security researcher Specter, and later confirmed by PeckShieldAlert through on-chain fund tracing.
The protocol operates across Ethereum, Solana, and Tron, positioning itself as a confidential transaction layer for stablecoins. Its pitch has centered on letting institutions and privacy-minded users move funds without exposing wallet history, which makes the breach especially damaging for a product built around that promise.
A proofless deposit path appears to be the entry point
According to the public alerts, the wallet tied to the exploit was 0xbB3f01a1b1C68F3DEB36C55342b5F5706c32fc20. That address executed what was described as a “Proofless Deposit” and then followed up with several “Transact” calls against the Hinkal contract.
Based on the available reporting, the attacker found a way to bypass a verification step that should have blocked a deposit from going through without proof. After that check failed, the method was repeated and close to 800,000 USDC was withdrawn. The case is another reminder that privacy-focused smart contracts still depend on ordinary logic checks working exactly as intended.
Stolen funds were mixed and then bridged
PeckShield’s tracking shows that 410 ETH, worth about $700,000, was sent to Tornado Cash after the exploit. That move is widely associated with attempts to obscure the trail between stolen assets and later destinations.
Another 44.7 ETH was bridged to Bitcoin through Thorchain and ended up at the address bc1qr2sf...zn3w. Moving value from Ethereum to Bitcoin through a cross-chain route is a familiar laundering pattern in major hacks because it shifts the assets away from the chain under the closest watch. In this case, the sequence was direct: mix first, then bridge.
The breach puts extra pressure on privacy DeFi projects
Hinkal had been drawing attention for its privacy features and stablecoin use cases, so the exploit spread quickly across crypto circles. A protocol built to protect transaction confidentiality was hit through a deposit validation flaw, and that contrast has become part of the story itself.
The public reports also point to a broader issue for users of privacy-based DeFi tools: an audit before launch does not guarantee safety after deployment. Ongoing contract reviews, live anomaly detection, and faster incident response matter just as much once real funds are active on-chain. For now, there is no public confirmation on whether any assets will be recovered or when a full fix will be completed.

