Technical Mechanism of the Exploit
Published 6/8/2026, 1:47:17 AM
The Fluid Merkle rewards exploit resulted in the loss of approximately 112,883 FLUID (often cited as 125K in early reports) and 47,903 GHO, totaling roughly $215,000 in value [Source: https://intellectia.ai/news/crypto/fluid-rewards-system-breach-leads-to-215k-loss]. The incident occurred on May 27, 2026, and was driven by a compromise of off-chain infrastructure rather than a flaw in the protocol's core smart contracts [Source: https://x.com/0xfluid/article/2061637830091157678].
Technical Mechanism of the Exploit
The exploit targeted the Merkle rewards distribution system, which relied on a two-key authorization process to update reward allocations.
- Private Key Compromise: The attacker gained control of both the proposer and approver private keys used for the off-chain Merkle root management [Source: https://www.mexc.com/news/1125907].
- Malicious Root Injection: With both keys, the attacker was able to propose and immediately approve a fraudulent Merkle root on-chain.
- "Empty-Proof" Claims: By manipulating the Merkle tree, the attacker created a state where they could execute reward claims using "empty proofs," allowing them to drain the tokens held in the rewards contract [Source: https://x.com/leviathan_news/status/2061126570006200529].
Impact and Recovery
The core Fluid protocol (Lending, Vaults, and DEX) remained secure as it is governed by a separate 7/14 multisig that was not affected by this breach [Source: https://www.panewslab.com/en/articles/019e827e-f470-713e-bd5d-e3c817357260].
| Metric | Data Point |
|---|---|
| Total FLUID Lost | 112,883 FLUID [Source: https://intellectia.ai/news/crypto/fluid-rewards-system-breach-leads-to-215k-loss] |
| Total GHO Lost | 47,903 GHO [Source: https://www.panewslab.com/en/articles/019e827e-f470-713e-bd5d-e3c817357260] |
| Estimated USD Loss | ~$215,000 [Source: https://www.mexc.com/news/1125907] |
| Containment Time | Within 10 hours of detection |
| Post-Exploit Action | Stolen funds converted to ETH and sent to Tornado Cash |
Data Gaps: While the mechanism and total losses are well-documented, specific transaction hashes for the drain or the attacker's wallet addresses were not provided in the available research data.
In summary, the exploit was a classic operational security failure where the compromise of two critical off-chain keys allowed an attacker to bypass the Merkle verification logic and withdraw rewards they were not entitled to.