Flamincome Hack

Reported loss $346K
Flash Loan Attack

What happened

On September 16, 2026, legacy Ethereum yield-aggregator Flamincome (associated with Flamingo Finance) suffered an oracle and vault share price manipulation exploit, resulting in a net attacker profit of $345,902.67 USDT via an $18.09 million Morpho flash loan.

The attacker targeted legacy 2020-era VaultYUSDT strategy contracts that calculated asset holdings and share values using Curve's manipulable virtual price. Using an $18.09 million USDT flash loan borrowed from Morpho, the attacker staked Curve USDP LP tokens into the strategy contract to artificially inflate the vault's share pricing and Net Asset Value (NAV). With the share valuation artificially elevated, the attacker redeemed their oversized shares for liquid aUSDT from Aave at a favorable exchange rate, repaid the $18.09 million flash loan in the same atomic transaction, and extracted $345,902.67 USDT in profit.

On-Chain Key Addresses:

Attacker Primary Address: 0x83381e7f…c36871

Target Strategy / Vault: 0xb8d6471c…e268a5

Exploit Contract 1: 0x875da4bd…65d2e6

Exploit Contract 2: 0x1c7eacef…d8b486

Protocol details

Classification Yield Aggregator
Protocol Type Exploit/Flash Loan Attack

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.