Flamincome Hack
What happened
On September 16, 2026, legacy Ethereum yield-aggregator Flamincome (associated with Flamingo Finance) suffered an oracle and vault share price manipulation exploit, resulting in a net attacker profit of $345,902.67 USDT via an $18.09 million Morpho flash loan.
The attacker targeted legacy 2020-era VaultYUSDT strategy contracts that calculated asset holdings and share values using Curve's manipulable virtual price. Using an $18.09 million USDT flash loan borrowed from Morpho, the attacker staked Curve USDP LP tokens into the strategy contract to artificially inflate the vault's share pricing and Net Asset Value (NAV). With the share valuation artificially elevated, the attacker redeemed their oversized shares for liquid aUSDT from Aave at a favorable exchange rate, repaid the $18.09 million flash loan in the same atomic transaction, and extracted $345,902.67 USDT in profit.
On-Chain Key Addresses:
Attacker Primary Address: 0x83381e7f…c36871
Target Strategy / Vault: 0xb8d6471c…e268a5
Exploit Contract 1: 0x875da4bd…65d2e6
Exploit Contract 2: 0x1c7eacef…d8b486
Protocol details
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.