Incident case file
Sign in to watchFluid — Off-Chain Merkle Rewards Key Compromise Drains Distribution Contract
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: MISSING — attacker address not publicly disclosed by Fluid team or any security firm | Tx hash: MISSING — not published | Note: exploit targeted off-chain infrastructure (proposer and approver operational keys for Merkle rewards distribution), not the core protocol smart contracts
Timeline: May 27, 2026 (estimated) — Attacker compromises the proposer and approver operational keys of Fluid's off-chain Merkle rewards distribution infrastructure. Using the compromised keys, attacker submits fraudulent Merkle roots associated with empty proofs to the rewards distribution contract, enabling unauthorized claims of ~163,706 FLUID and ~51,900 GHO (~$215,000 total). May 31, 2026 19:37 UTC — @0xfluid publishes official incident disclosure: 'We identified and contained a compromise affecting our off-chain merkle rewards distribution infrastructure. Importantly: The core protocol remains fully secure and is governed by governance and the 7/14 team multisig. All protocol smart contracts are safe and unaffected. User funds are not at risk from this incident. The impacted contract is not part of the core protocol infrastructure and was used solely for rewards distribution with minimal funds in its balance. Our team is actively investigating the incident. We will share a detailed post-mortem as soon as possible.' May 31, 2026 — Fluid team revokes compromised keys, pauses reward claims, and initiates upgrade. Protocol confirms it will cover all losses from treasury. Core lending, DEX, and user funds confirmed unaffected throughout. Post May 31, 2026 — SlowMist Hacked records incident dated 2026-05-31 with $215,000 loss and 'Private Key Leakage' attack method. Full post-mortem not published within reporting window.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)