Go to app

Technical Mechanism of the Exploit

Published 6/8/2026, 1:47:17 AM

The Fluid Merkle rewards exploit resulted in the loss of approximately 112,883 FLUID (often cited as 125K in early reports) and 47,903 GHO, totaling roughly $215,000 in value [Source: https://intellectia.ai/news/crypto/fluid-rewards-system-breach-leads-to-215k-loss]. The incident occurred on May 27, 2026, and was driven by a compromise of off-chain infrastructure rather than a flaw in the protocol's core smart contracts [Source: https://x.com/0xfluid/article/2061637830091157678].

Technical Mechanism of the Exploit

The exploit targeted the Merkle rewards distribution system, which relied on a two-key authorization process to update reward allocations.

  • Private Key Compromise: The attacker gained control of both the proposer and approver private keys used for the off-chain Merkle root management [Source: https://www.mexc.com/news/1125907].
  • Malicious Root Injection: With both keys, the attacker was able to propose and immediately approve a fraudulent Merkle root on-chain.
  • "Empty-Proof" Claims: By manipulating the Merkle tree, the attacker created a state where they could execute reward claims using "empty proofs," allowing them to drain the tokens held in the rewards contract [Source: https://x.com/leviathan_news/status/2061126570006200529].

Impact and Recovery

The core Fluid protocol (Lending, Vaults, and DEX) remained secure as it is governed by a separate 7/14 multisig that was not affected by this breach [Source: https://www.panewslab.com/en/articles/019e827e-f470-713e-bd5d-e3c817357260].

MetricData Point
Total FLUID Lost112,883 FLUID [Source: https://intellectia.ai/news/crypto/fluid-rewards-system-breach-leads-to-215k-loss]
Total GHO Lost47,903 GHO [Source: https://www.panewslab.com/en/articles/019e827e-f470-713e-bd5d-e3c817357260]
Estimated USD Loss~$215,000 [Source: https://www.mexc.com/news/1125907]
Containment TimeWithin 10 hours of detection
Post-Exploit ActionStolen funds converted to ETH and sent to Tornado Cash

Data Gaps: While the mechanism and total losses are well-documented, specific transaction hashes for the drain or the attacker's wallet addresses were not provided in the available research data.

In summary, the exploit was a classic operational security failure where the compromise of two critical off-chain keys allowed an attacker to bypass the Merkle verification logic and withdraw rewards they were not entitled to.