$346,000 Lost in FlamingoFinance DeFi Exploit via Flash Loan Manipulation
FlamingoFinance lost approximately $346,000 in a DeFi exploit after an attacker manipulated share prices in older Flamincome contracts.
According to security firm Blockaid, the attacker used an $18 million USDT flash loan to inflate VaultYUSDT's share price and then redeem liquid aUSDT at a favorable rate.
The exploit occurred on September 16, 2026, and was detected by Blockaid's exploit detection system. The affected contracts were part of older Flamincome deployments.
Blockaid identified several wallet addresses linked to the exploit and the main transaction used in the attack, but did not disclose the full mechanics of the pricing flaw.