Incident case file
Sign in to watchSmartCredit Leveraged Lido Module — Flash Loan Exploit
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: TODO — not disclosed in SlowMist snippet, single-source MEXC alert
Timeline: On May 4, 2026, an attacker exploited the Leveraged Lido module of SmartCredit on Ethereum via a flash loan attack. By temporarily borrowing large capital, the attacker manipulated the lending mechanism's internal accounting to extract approximately $72,000. SmartCredit paused the Leveraged Lido functionality immediately upon detection and confirmed via its official X account that the protocol's Loss Provision Fund (LPF) would fully cover the gap for affected stakers. As a result, no end-user funds were ultimately at risk. SlowMist classified the incident as a Flash Loan Exploit. The attacker EOA has not been publicly disclosed in available sources.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)