Fact-check findings
What an automated fact-checker found when it re-read Hinkal Protocol against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
disputed
5 claimsThe reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.
- #6[disputed][awaiting moderator]in section: Overview and Background
“The protocol raised a $1.4 million seed round in April 2024 from investors including SALT Fund (led by AJ Scaramucci), Draper Associates, SNZ Capital, and Peer VC, at a reported valuation of $70 million.”
reviewerThe protocol raised a $1.4 million seed round in April 2024 from SALT Fund, Draper Associates, SNZ Capital, and Peer VC at a $70 million valuation.The page's own timeline entry for this event correctly calls it a 'strategic funding round,' but the Overview section mislabels it a 'seed round,' contradicting both the cited press release and Hinkal's actual (larger, earlier) $4.1M November 2023 seed round.Proposed correction (not yet applied)The protocol raised a $1.4 million strategic funding round in April 2024 from investors including SALT Fund (led by AJ Scaramucci), Draper Associates, SNZ Capital, and Peer VC, at a reported valuation of $70 million. - #10[disputed][awaiting moderator]in section: July 2026 Smart Contract Exploit
“then executed at least 14 transact() calls in rapid succession, each draining 25,000 USDC”
reviewerThe attacker initiated a prooflessDeposit() call using a legacy-format note, then executed at least 14 transact() calls in rapid succession, each draining 25,000 USDC.No cited or independently found source states '14' transact() calls against the Hinkal contract; the only source giving a specific transaction count (AML Crypto) puts it at 85. The number 14 corresponds instead to a separate batch of Tornado Cash deposit transactions in the laundering stage, suggesting the figure was misattributed.Proposed correction (not yet applied)then executed multiple transact() calls in rapid succession, each draining 25,000 USDC - #16[disputed][awaiting moderator]in section: Protocol Response and User Reimbursement
“No information on protocol restart or resumed operations has been confirmed as of August 20, 2026.”
reviewerNo information on protocol restart or resumed operations has been confirmed as of August 20, 2026.The page states no restart/resumption information was available as of Aug 20, 2026, but a company-issued press release with direct CEO quotes announcing a new product launch was published Aug 14, 2026, predating that cutoff and contradicting the claim of no available information.Proposed correction (not yet applied)Hinkal announced a new AI-powered confidential stablecoin payments product on August 14, 2026, indicating the protocol had resumed development and public-facing operations before the page's August 20, 2026 reporting cutoff. - #19[disputed][awaiting moderator]in the timeline
“2024-09-02”
reviewerzkSecurity completed its audit of Hinkal on September 2, 2024.September 2, 2024 was the audit engagement start date, not the completion date; the report was finalized September 6, 2024. The timeline event text ('zkSecurity completes a security audit') is only accurate if the date is corrected to September 6.Proposed correction (not yet applied)2024-09-06 - #22[disputed][awaiting moderator]in the timeline
“executing 14+ automated withdrawals of 25,000 USDC each and draining approximately $820,000”
reviewerAttacker exploits prooflessDeposit(), executing 14+ automated withdrawals of 25,000 USDC each, draining approximately $820,000 — nearly the protocol's entire TVL of $829,000; CertiK flags the attack in real time.Same underlying defect as the parallel finding in sections[1]: no source supports a specific count of '14' transact() calls against the Hinkal contract.Proposed correction (not yet applied)executing multiple automated withdrawals of 25,000 USDC each and draining approximately $820,000
unverifiable
1 claimNo source the reviewer could reach confirms or contradicts the claim.
- #4[unverifiable][awaiting moderator]in the summary
“no confirmed recovery of stolen funds had been reported as of August 20, 2026”
reviewerNo confirmed recovery of stolen funds had been reported as of August 20, 2026.This is a negative claim (absence of reporting) that cannot be conclusively verified either way with available search results.
partially supported
2 claimsThe cited evidence supports part of the claim but not all of it.
- #2[partially supported][awaiting moderator]in the summary
“On July 3–4, 2026, an attacker exploited a business-logic flaw in its legacy note format to drain approximately $820,000 in USDC from its Ethereum deployment — representing nearly all of the protocol's total value locked.”
reviewerOn July 3-4, 2026 an attacker drained approximately $820,000 in USDC representing nearly all of Hinkal's TVL via a business-logic flaw in the legacy note format.The $820,000 figure is the widely-reported initial estimate and is not wrong per se, but at least two of the page's own cited/related sources (Crypto Adventure, AML Crypto) later revised the total downward to ~$797K and ~$772K respectively; the page does not acknowledge this variance anywhere. - #5[partially supported][awaiting moderator]in section: Overview and Background
“Hinkal positioned itself as institutional-grade privacy infrastructure and reported over $500 million in historical private transaction volume before the July 2026 incident.”
reviewerHinkal reported over $500 million in historical private transaction volume before the July 2026 incident.The $500M figure traces to Hinkal's own promotional material rather than an independent audit of on-chain volume; presented on the page as a flat fact without noting it is self-reported.
confirmed
16 claimsThe cited evidence supports the claim as written.
- #1[confirmed][no action needed]in the summary
“Hinkal Protocol is a zero-knowledge proof-based privacy DeFi protocol founded by Georgi Koreli and Nika Koreli, operating on Ethereum and multiple other chains, that enables confidential on-chain transactions for institutional users.”
reviewerHinkal Protocol was co-founded by Georgi Koreli and Nika Koreli, both with Stanford ties.Founder names and Stanford affiliation are independently corroborated by Stanford's own alumni page and industry press. - #3[confirmed][no action needed]in the summary
“Hinkal subsequently committed to full 1:1 user reimbursement and paused all smart contracts pending a postmortem; no confirmed recovery of stolen funds had been reported as of August 20, 2026.”
reviewerHinkal committed to full 1:1 user reimbursement and paused all smart contracts pending a postmortem.Reimbursement pledge and contract pause are directly confirmed by quoted Hinkal statements in press coverage. - #7[confirmed][no action needed]in section: Overview and Background
“at a reported valuation of $70 million”
reviewerSALT Fund (led by AJ Scaramucci), Draper Associates, SNZ Capital, and Peer VC participated in a $1.4M round at a $70M valuation.Investor list and valuation independently confirmed by The Block's reporting. - #8[confirmed][no action needed]in section: July 2026 Smart Contract Exploit
“an attacker with the address 0xbB3f01a1b1C68F3DEB36C55342b5F5706c32fc20 exploited a critical business-logic vulnerability in Hinkal's Ethereum smart contract (0x25e5...a826)”
reviewerThe attacker's address was 0xbB3f01a1b1C68F3DEB36C55342b5F5706c32fc20 and Hinkal's exploited Ethereum contract was 0x25e5...a826.Both addresses are corroborated across independent security-firm and news reporting. - #9[confirmed][no action needed]in section: July 2026 Smart Contract Exploit
“the root cause was a flaw in Hinkal's legacy note format: a single deposit note was not cryptographically bound to a unique nullifier, meaning different (e, nk) pairs could produce the same commitment but different nullifiers. This enabled a double-spend pattern — one deposit could be withdrawn multiple times.”
reviewerThe root cause was a legacy note format flaw where a single deposit note was not cryptographically bound to a unique nullifier, allowing different (e, nk) pairs to produce the same commitment but different nullifiers, enabling a double-spend.Technical root-cause description closely tracks BlockSec's own published analysis, which is the primary technical source for this incident. - #11[confirmed][no action needed]in section: July 2026 Smart Contract Exploit
“The total loss of approximately $820,000 represented nearly the entire TVL of the protocol, which stood at roughly $829,000 across five chains at the time of the attack.”
reviewerThe total loss of approximately $820,000 represented nearly the entire TVL of the protocol, which stood at roughly $829,000 across five chains at the time of the attack.TVL figure and cross-chain count corroborated by multiple independent outlets. - #12[confirmed][no action needed]in section: July 2026 Smart Contract Exploit
“The incident was flagged in real time by blockchain security firm CertiK.”
reviewerThe incident was flagged in real time by blockchain security firm CertiK.Directly confirmed by the cited ChainCatcher article. - #13[confirmed][no action needed]in section: Fund Laundering via Tornado Cash and THORChain
“the attacker deposited approximately 410 ETH (valued at roughly $700,000) into Tornado Cash, and separately bridged 44.67 ETH from Ethereum to Bitcoin via THORChain, with the destination Bitcoin address beginning with bc1qr2sf”
reviewerThe attacker deposited approximately 410 ETH (~$700,000) into Tornado Cash and separately bridged 44.67 ETH from Ethereum to Bitcoin via THORChain, with the destination address beginning bc1qr2sf.Laundering route, amounts, and destination address prefix independently confirmed by multiple sources including on-chain forensic analysis. - #14[confirmed][no action needed]in section: Protocol Response and User Reimbursement
“The team reported the incident to U.S. federal law enforcement and engaged external security specialists to validate preliminary findings before publishing a full postmortem.”
reviewerHinkal reported the incident to U.S. federal law enforcement and engaged external security specialists to validate preliminary findings before publishing a full postmortem.Both the law-enforcement referral and external validation process are directly quoted in the cited source. - #15[confirmed][no action needed]in section: Protocol Response and User Reimbursement
“In a public statement, Hinkal committed to reimbursing all affected users 1:1, stating that 'all affected funds will be returned in full.'”
reviewerIn a public statement, Hinkal committed to reimbursing all affected users 1:1, stating 'all affected funds will be returned in full.'Quote and reimbursement commitment verified verbatim in the cited article. - #17[confirmed][no action needed]in section: Prior Security Audit
“The audit identified six findings: two medium-severity issues (a blacklisting bypass and unbound encrypted outputs), two low-severity issues, and two informational issues. No critical vulnerabilities were flagged.”
reviewerzkSecurity commissioned/completed a security audit of Hinkal's Solidity contracts and Circom circuits in September 2024, identifying six findings (two medium, two low, two informational) with no critical vulnerabilities.Finding count and severity breakdown match the primary audit report exactly, including the specific medium-severity issue descriptions. - #18[confirmed][no action needed]in section: Prior Security Audit
“The audit did not identify the nullifier-binding flaw in the legacy note format that was ultimately exploited in July 2026, suggesting the vulnerability either post-dated the audit scope, was present in code not reviewed, or was missed during the review.”
reviewerThe audit did not identify the nullifier-binding flaw in the legacy note format that was ultimately exploited in July 2026.Reasonable and appropriately hedged inference; the audit's published finding list contains no reference to the nullifier-binding defect later described by BlockSec. - #20[confirmed][no action needed]in the timeline
“Hinkal Protocol founded by Georgi Koreli and Nika Koreli, incubated at Stanford.”
reviewerHinkal Protocol founded by Georgi Koreli and Nika Koreli in 2022, incubated at Stanford.Founding year and Stanford incubation independently corroborated; cited Tracxn URL is live (200 status) though it blocks the automated fetch tool used in this review. - #21[confirmed][no action needed]in the timeline
“Hinkal closes a $1.4 million strategic funding round at a $70 million valuation, led by SALT Fund (AJ Scaramucci), with participation from Draper Associates, SNZ Capital, and Peer VC.”
reviewerHinkal closes a $1.4 million strategic funding round at a $70 million valuation on 2024-04-26, led by SALT Fund (AJ Scaramucci), with participation from Draper Associates, SNZ Capital, and Peer VC.This timeline entry is accurate and, notably, correctly labels the round 'strategic' — unlike the Overview section's inconsistent 'seed round' framing (see related finding). - #23[confirmed][no action needed]in the timeline
“Hinkal pauses all smart contracts across all chains as a precautionary measure and reports the incident to U.S. federal law enforcement.”
reviewerHinkal pauses all smart contracts across all chains as a precautionary measure and reports the incident to U.S. federal law enforcement (2026-07-03).Directly confirmed by cited source. - #24[confirmed][no action needed]in the timeline
“Hinkal publicly commits to reimbursing all affected users 1:1, stating all affected funds will be returned in full. Specific process and timeline withheld pending technical fix verification.”
reviewerHinkal publicly commits to reimbursing all affected users 1:1 on 2026-07-04, stating all affected funds will be returned in full.Consistent with the same claim verified in sections[3].