Security monitoring on September 16 identified an exploit involving older Flamincome contracts associated with Flamingo Finance.
The attacker used a large flash loan to manipulate vault share accounting rather than attacking a base-layer blockchain or compromising user private keys.
Attack sequence
- The attacker borrowed approximately $18 million in USDT through a flash loan.
- The attacker interacted with Curve USDP LP assets held by a strategy.
- The LP position was used to inflate the VaultYUSDT share price.
- The attacker redeemed liquid aUSDT at a distorted exchange rate.
- Security monitoring reported approximately $345,900 USDT in attacker profit.
The $18 million flash-loan amount is not the protocol loss. It was temporary borrowed liquidity used to amplify the manipulation.
What failed?
The key risk appears to be vault share-price accounting in older Flamincome deployments. Vault systems convert between strategy assets, vault shares, accrued yield and redeemable claims. If an attacker can temporarily inject value into the accounting base and cause the vault to calculate a higher share value, they may redeem more liquid assets than their real economic contribution justifies.
Why flash loans matter
Flash loans let an attacker temporarily control large capital without maintaining it before or after the transaction. The relevant security question is whether protocol accounting remains correct when an adversary can borrow $18 million for one transaction.
Old contracts versus current Flamingo
Security reporting described the affected deployments as older Flamincome contracts. CEXVia therefore does not assume every Flamingo Finance product is compromised.
At the time of the reviewed reporting, a complete Flamingo incident report defining every affected contract, user balance and remediation step was not yet available.
Attacker profit versus final protocol loss
The reported $345,900 figure is attacker profit at disclosure. It should not automatically be written as final protocol loss, LP loss or user reimbursement amount.
Evidence Status
Confirmed / Security Monitoring + On-chain Reporting
Exploit detected Sep. 16; older Flamincome contracts involved; ~$18M USDT flash loan; Curve USDP LP strategy interaction; VaultYUSDT share-price inflation; ~$345.9K attacker profit.
Developing
Full root cause, final protocol/user loss, recovery, complete affected-contract list, remediation and compensation.
Risk Assessment
High. The dollar amount is moderate relative to 2026’s largest incidents, but the failure class matters because vault-accounting manipulation can recur anywhere similar assumptions remain.
What to Watch Next
Flamingo post-mortem, affected contract inventory, paused functions, attacker fund movement, recovery and migration away from legacy contracts.
FAQ
Did Flamingo lose $18 million?
No. About $18M was temporary flash-loan liquidity.
How much did the attacker make?
About $345,900 USDT was reported at disclosure.
What was manipulated?
VaultYUSDT share-price accounting in older Flamincome contracts.
Was a base chain compromised?
No evidence reviewed indicates a base-layer consensus compromise.
Are all Flamingo products affected?
A broader compromise is not established.
Is $345.9K the final loss?
Not yet; it is best treated as current attacker profit/extraction pending full accounting.