← Radar

Incident case file

Sign in to watch

Fluid — Off-Chain Merkle Rewards Key Compromise Drains Distribution Contract

Incident date May 31, 2026

0 views

ContainedEthereumInfrastructure / Private Key LeakageCluster: FLUID-MERKLE-2026-05

Estimated loss

$215K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Attacker: MISSING — attacker address not publicly disclosed by Fluid team or any security firm | Tx hash: MISSING — not published | Note: exploit targeted off-chain infrastructure (proposer and approver operational keys for Merkle rewards distribution), not the core protocol smart contracts

Funds moved to: ~$215,000 total loss: ~163,706 FLUID tokens + ~51,900 GHO tokens drained from Merkle rewards distribution contract. Laundering path: MISSING — not publicly disclosed. Fluid team confirms keys revoked and claims paused. Fluid pledges to cover all losses from protocol treasury (users not affected — only protocol-owned reward funds at risk).
Impacted contract: Fluid off-chain Merkle rewards distribution infrastructure (specific contract address MISSING — not published by team). Core Fluid lending protocol, DEX contracts, and user funds confirmed unaffected. The attack used compromised proposer and approver operational keys to submit fraudulent Merkle roots with empty proofs, allowing the attacker to claim rewards without valid entitlements. Fluid team revoked compromised keys immediately upon discovery and paused all reward claims

Timeline: May 27, 2026 (estimated) — Attacker compromises the proposer and approver operational keys of Fluid's off-chain Merkle rewards distribution infrastructure. Using the compromised keys, attacker submits fraudulent Merkle roots associated with empty proofs to the rewards distribution contract, enabling unauthorized claims of ~163,706 FLUID and ~51,900 GHO (~$215,000 total). May 31, 2026 19:37 UTC — @0xfluid publishes official incident disclosure: 'We identified and contained a compromise affecting our off-chain merkle rewards distribution infrastructure. Importantly: The core protocol remains fully secure and is governed by governance and the 7/14 team multisig. All protocol smart contracts are safe and unaffected. User funds are not at risk from this incident. The impacted contract is not part of the core protocol infrastructure and was used solely for rewards distribution with minimal funds in its balance. Our team is actively investigating the incident. We will share a detailed post-mortem as soon as possible.' May 31, 2026 — Fluid team revokes compromised keys, pauses reward claims, and initiates upgrade. Protocol confirms it will cover all losses from treasury. Core lending, DEX, and user funds confirmed unaffected throughout. Post May 31, 2026 — SlowMist Hacked records incident dated 2026-05-31 with $215,000 loss and 'Private Key Leakage' attack method. Full post-mortem not published within reporting window.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)