Risk Radar

/ high

Flamingo / Flamincome Exploit: $18M Flash Loan Manipulates VaultYUSDT Share Price

An attacker used an ~$18M USDT flash loan to manipulate VaultYUSDT pricing in older Flamincome contracts and extracted about $345.9K in USDT profit.

September 17, 2026Last updated 10:30 UTC3 min read

Security monitoring on September 16 identified an exploit involving older Flamincome contracts associated with Flamingo Finance.

The attacker used a large flash loan to manipulate vault share accounting rather than attacking a base-layer blockchain or compromising user private keys.

Attack sequence

  1. The attacker borrowed approximately $18 million in USDT through a flash loan.
  2. The attacker interacted with Curve USDP LP assets held by a strategy.
  3. The LP position was used to inflate the VaultYUSDT share price.
  4. The attacker redeemed liquid aUSDT at a distorted exchange rate.
  5. Security monitoring reported approximately $345,900 USDT in attacker profit.

The $18 million flash-loan amount is not the protocol loss. It was temporary borrowed liquidity used to amplify the manipulation.

What failed?

The key risk appears to be vault share-price accounting in older Flamincome deployments. Vault systems convert between strategy assets, vault shares, accrued yield and redeemable claims. If an attacker can temporarily inject value into the accounting base and cause the vault to calculate a higher share value, they may redeem more liquid assets than their real economic contribution justifies.

Why flash loans matter

Flash loans let an attacker temporarily control large capital without maintaining it before or after the transaction. The relevant security question is whether protocol accounting remains correct when an adversary can borrow $18 million for one transaction.

Old contracts versus current Flamingo

Security reporting described the affected deployments as older Flamincome contracts. CEXVia therefore does not assume every Flamingo Finance product is compromised.

At the time of the reviewed reporting, a complete Flamingo incident report defining every affected contract, user balance and remediation step was not yet available.

Attacker profit versus final protocol loss

The reported $345,900 figure is attacker profit at disclosure. It should not automatically be written as final protocol loss, LP loss or user reimbursement amount.

Evidence Status

Confirmed / Security Monitoring + On-chain Reporting

Exploit detected Sep. 16; older Flamincome contracts involved; ~$18M USDT flash loan; Curve USDP LP strategy interaction; VaultYUSDT share-price inflation; ~$345.9K attacker profit.

Developing

Full root cause, final protocol/user loss, recovery, complete affected-contract list, remediation and compensation.

Risk Assessment

High. The dollar amount is moderate relative to 2026’s largest incidents, but the failure class matters because vault-accounting manipulation can recur anywhere similar assumptions remain.

What to Watch Next

Flamingo post-mortem, affected contract inventory, paused functions, attacker fund movement, recovery and migration away from legacy contracts.

FAQ

Did Flamingo lose $18 million?

No. About $18M was temporary flash-loan liquidity.

How much did the attacker make?

About $345,900 USDT was reported at disclosure.

What was manipulated?

VaultYUSDT share-price accounting in older Flamincome contracts.

Was a base chain compromised?

No evidence reviewed indicates a base-layer consensus compromise.

Are all Flamingo products affected?

A broader compromise is not established.

Is $345.9K the final loss?

Not yet; it is best treated as current attacker profit/extraction pending full accounting.