Hinkal privacy protocol exploited; team offers white-hat recovery deal requiring 90% return within 72 hours or law enforcement escalation.
Security & Exploits ·
The Hinkal privacy protocol team posted an on-chain message to the address holding exploited funds, offering a settlement deal: return 90% of the stolen assets to the protocol owner address and retain 10% as a white-hat recovery arrangement. The proposal comes with a 72-hour deadline, expiring July 11 at 23:59 UTC, after which the team indicated it will escalate to law enforcement.
The message frames the offer as a path to avoid civil action and public attribution as an attacker, positioning the recovery as a way to contain reputational damage for the person or group responsible. The team noted that moving the funds without exposure becomes increasingly difficult over time, adding pressure to the deadline. The message was sent directly to the address holding the stolen funds and included a contact email for negotiation.
It remains unclear whether the exploit has been formally disclosed, the total amount at stake, or the technical vulnerability exploited. No confirmation has emerged on whether the deadline will be met or whether the team will follow through on law enforcement involvement if the funds are not returned.