FlamingoFinance lost about $345,900 in a DeFi exploit after an attacker manipulated share prices in older Flamincome contracts, security firm Blockaid said Wednesday.
The attacker used an $18 million USDT flash loan to increase the size of the trade and exploit the pricing flaw. The borrowed funds were used to interact with USDP liquidity-provider tokens held by a strategy contract.
Flash Loan Drives Vault Manipulation
Blockaid said the attack inflated VaultYUSDT’s share price, allowing the attacker to redeem liquid aUSDT at a favorable rate.
Related: Zerodha’s Kamath Backs UPI MDR but Flags Risk to Zero-Brokerage Model
The security firm identified several wallet addresses linked to the exploit and the main transaction used in the attack. One address held little ETH afterward. Blockchain records show it had received 0.1 ETH from Tornado Cash before the exploit, then later moved 144.15 ETH and interacted with LI.FI.
Blockaid did not disclose the full mechanics of the pricing flaw. The affected contracts were part of older Flamincome deployments.
DeFi Exploits Continue
The FlamingoFinance incident follows other recent attacks targeting DeFi protocols. Chainflip halted its network after an attacker drained $736,442 from its Tron USDT route.
Zentra Finance also reported a $143,000 exploit involving its ctUSD reserve. The incidents highlight continued risks involving smart-contract vulnerabilities and liquidity systems across DeFi platforms.
Related: Spain Says Europe’s Digital Asset Rules May Be Too Restrictive
Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.