BitcoinWorld Fluid Loses $215,000 in Reward System Exploit After Key Compromise Decentralized finance protocol Fluid has lost approximately $215,000 after itsBitcoinWorld Fluid Loses $215,000 in Reward System Exploit After Key Compromise Decentralized finance protocol Fluid has lost approximately $215,000 after its

Fluid Loses $215,000 in Reward System Exploit After Key Compromise

2026/06/01 18:10
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

BitcoinWorld

Fluid Loses $215,000 in Reward System Exploit After Key Compromise

Decentralized finance protocol Fluid has lost approximately $215,000 after its Ethereum-based reward distribution system was exploited earlier this week, according to a report from DeFi risk intelligence platform BlackHart. The incident stemmed from compromised operational keys rather than a flaw in the underlying smart contract code.

How the Exploit Unfolded

The attacker gained control of two operational keys used to create and approve reward lists within the protocol. Using this access, they registered and approved a reward list that directed all distributions to a single address under their control. The funds were then claimed and quickly moved. Fluid confirmed that the exploit did not affect its lending markets, vaults, decentralized exchange, or user deposits.

The stolen assets included 112,883 FLUID tokens, 47,903 GHO, and a small amount of cbBTC. The attacker swapped these assets for Ether and transferred the proceeds through Tornado Cash, a privacy tool commonly used to obfuscate transaction trails.

Response and Remediation

Fluid stated that it has replaced the compromised keys and moved the remaining reward funds to a secure address. The project emphasized that the incident was contained to the reward distribution system and that core protocol functions remain operational. The exploit highlights a persistent vulnerability in DeFi: the security of off-chain operational infrastructure.

Why This Matters for DeFi Users

While smart contract audits are standard practice, the Fluid incident underscores that key management is equally critical. Compromised administrative keys can bypass even the most rigorously audited code. For users, this event reinforces the importance of protocols that employ multi-signature governance, time-locks, and decentralized key management to reduce single points of failure.

The use of Tornado Cash in laundering the stolen funds also brings renewed attention to regulatory scrutiny around privacy tools, especially after U.S. sanctions against the platform in 2022. The incident may prompt further discussion on how DeFi protocols can balance transparency with operational security.

Conclusion

The Fluid exploit serves as a reminder that DeFi security extends beyond smart contract audits. As the industry matures, robust key management and operational security practices will be essential to maintaining user trust and preventing similar breaches. Fluid has taken immediate corrective action, but the incident adds to a growing list of attacks targeting administrative infrastructure rather than code vulnerabilities.

FAQs

Q1: Was the Fluid exploit caused by a smart contract bug?
No. The attacker compromised two operational keys used to create and approve reward lists, not a vulnerability in the smart contract code itself.

Q2: Were user deposits or lending markets affected?
Fluid confirmed that its lending markets, vaults, DEX, and user deposits were not impacted. Only the reward distribution system was exploited.

Q3: How did the attacker launder the stolen funds?
The attacker swapped the stolen assets for Ether and transferred them through Tornado Cash, a privacy mixer that obscures transaction trails.

This post Fluid Loses $215,000 in Reward System Exploit After Key Compromise first appeared on BitcoinWorld.

시장 기회
인스타댑 로고
인스타댑 가격(FLUID)
$1.0951
$1.0951$1.0951
-3.19%
USD
인스타댑 (FLUID) 실시간 가격 차트

Predict & Trade to Win Rewards

Predict & Trade to Win RewardsPredict & Trade to Win Rewards

Guaranteed rewards with $500,000 prize pool

면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

RealStocks Now Live

RealStocks Now LiveRealStocks Now Live

Trade real U.S. stock via regulated brokerage