Fluid Lending Hack
What happened
On May 31, 2026, Fluid publicly disclosed a compromise of its off-chain Merkle rewards distribution infrastructure. Forensic reporting links the underlying reward claims to May 27; the reported loss is approximately $215,000. The core lending, DEX, vault, and user-deposit systems were not affected.
The rewards workflow placed both root-proposal and approval authority in operational keys that were compromised; once both were controlled, the attacker could authorize self-serving roots and claim rewards. The exact key-exfiltration path is not publicly confirmed.
How it happened
An attacker controlled the operational proposer and approver keys, submitted and approved a self-serving Merkle root, and claimed rewards with empty proofs.
Protocol details
Security review history
- PeckShield View report
- Cantina View report
- MixBytes View report
Evidence
- analysis DeFiLlama defillama.com
- analysis SlowMist: Fluid rewards infrastructure compromise hacked.slowmist.io
- analysis CryptoTimes: Fluid Protocol loses FLUID and GHO in key compromise attack cryptotimes.io
- analysis BlackHart: Fluid Merkle Distributor key compromise blackhart.io
- analysis Delta Capital: Fluid Lending incident archive deltacapitalhk.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.