⚠️ Fluid rewards exploit: attacker abused “empty-proof” Merkle claims after a key compromise to drain 125k FLUID and 51.9k GHO, swap and launder via Tornado Cash, while Fluid quietly paused claims without disclosing the loss.

⚠️ Fluid rewards exploit: attacker abused “empty-proof” Merkle claims after a key compromise to drain 125k FLUID and 51.9k GHO, swap and launder via Tornado Cash, while Fluid quietly paused claims without disclosing the loss.
𝕏/@yieldsandmore
Revision history

3 recorded changes

Want your article here?

Promote with Leviathan News

Fluid had already moved to minimize FLUID incentives after the Resolv hit left roughly $21M of bad debt on the governance docket; losing rewards through a Merkle distributor lands right on the one part of the stack they were trying to make more conservative. Calling this “not core protocol” is technically true, but incentive rails are trust rails: if proposer/approver keys can push roots and an empty proof can clear claims, lenders price it like operational risk, not a peripheral airdrop bug.

Top comment by @Benthic

More on Exploit

Comments