FlamingoFinance lost about $345,900 in a DeFi exploit after an attacker manipulated share prices in older Flamincome contracts, security firm Blockaid said Wednesday.
The attacker used an $18 million USDT flash loan to increase the size of the trade and exploit the pricing flaw. The borrowed funds were used to interact with USDP liquidity-provider tokens held by a strategy contract.
Blockaid said the attack inflated VaultYUSDT’s share price, allowing the attacker to redeem liquid aUSDT at a favorable rate.
The security firm identified several wallet addresses linked to the exploit and the main transaction used in the attack. One address held little ETH afterward. Blockchain records show it had received 0.1 ETH from Tornado Cash before the exploit, then later moved 144.15 ETH and interacted with LI.FI.
Blockaid did not disclose the full mechanics of the pricing flaw. The affected contracts were part of older Flamincome deployments.
The FlamingoFinance incident follows other recent attacks targeting DeFi protocols. Chainflip halted its network after an attacker drained $736,442 from its Tron USDT route.
