Go to app

Exploit Mechanism

Published 6/8/2026, 10:35:05 AM

The Fluid Merkle exploit on May 27, 2026, resulted in the drainage of 125,000 FLUID and 51,900 GHO (valued at approximately $215,000) [Source: https://x.com/0xfluid/article/2061637830091157678]. The incident was caused by a compromise of off-chain operational keys rather than a vulnerability in the core protocol smart contracts.

Exploit Mechanism

The attack targeted the backend automation infrastructure responsible for managing reward distributions.

  • Key Compromise: Attackers gained control of two operational keys used by Fluid's backend to manage the Merkle rewards system [Source: https://m13digital.com/alerts].
  • Merkle Manipulation: Using these keys, the attacker manipulated the distribution logic by submitting "empty-proof" Merkle trees. This allowed them to bypass standard verification and trigger the claim functions on multiple reward distributors to extract assets intended for users.
  • Scope: The vulnerability was isolated to the off-chain automation layer. The core protocol, governed by a 7/14 team multisig, and all user deposits/collateral remained secure [Source: https://x.com/0xfluid/article/2061637830091157678].

Impact Summary

MetricValue
DateMay 27, 2026
FLUID Drained125,000 tokens
GHO Drained51,900 tokens
Total Estimated Loss~$215,000 USD
Primary CauseOperational Key Compromise
Affected SystemOff-chain Merkle distribution automation

Unresolved Data

While the methodology (compromised keys and empty-proof Merkle trees) is documented, specific transaction hashes or the exact smart contract addresses of the affected distributors were not provided in the available research data.

The protocol contained the breach within 24 hours and emphasized that the incident was a "control failure" of internal automation rather than a flaw in the Merkle tree logic itself [Source: https://x.com/0xfluid/article/2061637830091157678].

Next Steps:

  • Would you like to perform a technical analysis of the FLUID token's price action following this exploit?
  • I can monitor the Fluid protocol's official channels for the release of a full technical post-mortem including transaction hashes.