Fluid Lending Hack

Reported loss $215K
Ethereum
Operational Key Compromise

What happened

On May 31, 2026, Fluid publicly disclosed a compromise of its off-chain Merkle rewards distribution infrastructure. Forensic reporting links the underlying reward claims to May 27; the reported loss is approximately $215,000. The core lending, DEX, vault, and user-deposit systems were not affected.

Technical root cause

The rewards workflow placed both root-proposal and approval authority in operational keys that were compromised; once both were controlled, the attacker could authorize self-serving roots and claim rewards. The exact key-exfiltration path is not publicly confirmed.

How it happened

An attacker controlled the operational proposer and approver keys, submitted and approved a self-serving Merkle root, and claimed rewards with empty proofs.

Protocol details

Classification Frontend & Infrastructure
Protocol Type Lending
Implementation language Solidity
Protocol links Website @0xfluid

Security review history

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.