Flamingo Finance Exploited for Over 2 Trillion in Stolen FLM Tokens
Flamingo Finance, the primary DeFi platform on Neo N3, has been hit by an exploit through a vulnerability in its staking contract reward calculation.
The attacker minted approximately 2.19 trillion FLM tokens, more than 3,500 times the pre-exploit circulating supply of around 570 million, and used them to drain liquidity from the platform’s trading pools.
A flaw was discovered in the interaction between Flamingo's lending and staking contracts, where an incorrect reward calculation would produce inflated results. Atlazor, Flamingo's lead developer, explained that when the lending contract calls the staking contract to release LP tokens, the amount is calculated incorrectly.
Mr.Google, Flamingo team lead, described a compounding issue in the staking contract that could be triggered when extremely small amounts were withdrawn. The attacker exploited this flaw to claim massively inflated FLM rewards.