← Radar

Incident case file

Sign in to watch

Flamincome VaultYUSDT Flash Loan NAV Manipulation — $345.9K

Incident date Sep 15, 2026Last updated Sep 24, 2026

1 views

ActiveEthereumFlash loan / vault share-price inflationCluster: FLAMINCOME-ETH-2026-09

Estimated loss

$345.9K

Affected users

Number of affected users is not confirmed
Group joining is coming soon.

Investigation

55%

Facts and investigation

Ledger

Attacker

0x83381e7f7232775735169d72d237b858ffc36871

Funds moved to

Profit was kept as aUSDT redeemed from Aave following the inflated-NAV redemption; no laundering path publicly documented.

Linked

Attacker: 0x83381e7f7232775735169d72d237b858ffc36871. Targeted vault (legacy Flamingo Finance VaultYUSDT strategy): 0xb8d6471ca573c92c7096ab8600347f6a9fe268a5. Exploit contracts: 0x875da4bd7b4a52a806a533b1cf6d6ff92365d2e6 and 0x1c7eacef3630e764519e6ea2e8caa2bdb7d8b486.

Chronology

1 beat
  1. On September 16, 2026, an attacker exploited a legacy USDT strategy vault (VaultYUSDT, part of the deprecated Flamingo Finance contract set on Ethereum — distinct from the unrelated Flamingo Finance exploit on Neo N3 in late August). The attacker flash-loaned approximately 18 million USDT via Morpho, then injected a manipulated Curve USDP/3CRV LP position to artificially inflate the vault's share price (NAV). The attacker redeemed vault shares at the inflated rate for significantly more aUSDT from Aave than they were entitled to, repaid the flash loan, and kept the difference — a net profit of $345,902.67. The entire operation occurred within a single atomic transaction.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)