← Radar

Incident case file

Sign in to watch

SmartCredit Leveraged Lido Module — Flash Loan Exploit

Incident date May 4, 2026

0 views

ResolvedEthereumFlash loan exploitCluster: SMARTCREDIT-ETH-2026-05

Estimated loss

$72K

Victims identified

1
Victim group joining is coming soon.

Investigation

80%

Facts and investigation

Attacker: TODO — not disclosed in SlowMist snippet, single-source MEXC alert

Funds moved to: TODO — no public downstream trace
Affected module: SmartCredit Leveraged Lido. The attacker used a flash loan to temporarily borrow large capital, manipulated the lending mechanism, and extracted approximately $72K. The Leveraged Lido module was paused following detection. The protocol's Loss Provision Fund (LPF) fully covered the gap for affected stakers, so no end-user funds were ultimately lost.

Timeline: On May 4, 2026, an attacker exploited the Leveraged Lido module of SmartCredit on Ethereum via a flash loan attack. By temporarily borrowing large capital, the attacker manipulated the lending mechanism's internal accounting to extract approximately $72,000. SmartCredit paused the Leveraged Lido functionality immediately upon detection and confirmed via its official X account that the protocol's Loss Provision Fund (LPF) would fully cover the gap for affected stakers. As a result, no end-user funds were ultimately at risk. SlowMist classified the incident as a Flash Loan Exploit. The attacker EOA has not been publicly disclosed in available sources.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)