Fluid lost $215K after one attacker controlled both reward distribution keys, draining tokens through fake Merkle roots and routing proceeds to Tornado Cash. TheFluid lost $215K after one attacker controlled both reward distribution keys, draining tokens through fake Merkle roots and routing proceeds to Tornado Cash. The

$215K Stolen from Fluid: Attacker Controls Both Keys in Merkle Rewards System

For feedback or concerns regarding this content, please contact us at [email protected]

Fluid lost $215K after one attacker controlled both reward distribution keys, draining tokens through fake Merkle roots and routing proceeds to Tornado Cash.

The reward tokens were already gone. On May 27, an attacker who held both of Fluid’s operational signing keys pushed a fake reward list to the protocol’s Merkle distributors on Ethereum, Base, and Arbitrum. 

$215K Stolen from Fluid: Attacker Controls Both Keys in Merkle Rewards System

Fluid, the Ethereum-based DeFi protocol, uses a two-step system for distributing rewards: one key proposes a Merkle root and a second key approves it. As BlackHartInc on X reported, both of those roles were held by a single actor. The two-person control meant nothing once one person held both keys.

One Person, Two Keys, Zero Resistance 

The proposer key submitted a self-serving root to the FLUID distributor at 21:11:11 UTC. Twelve seconds later, the same attacker approved it using the approver key. Twenty-four seconds after the initial proposal, a claim went through using an empty Merkle proof.

That empty proof was not a bug. A single-entry reward list produces a root equal to its only leaf, so no proof path is needed. The contract verified it correctly. Nothing in the smart contract broke. Per forensic analysis by BlackHart, the entire failure was operational key custody.

The same propose-approve-claim cycle then ran against the GHO distributor at 21:13:59 UTC and a third distributor for a small cbBTC amount hours later. Across all three chains, the attacker walked away with roughly 125,109 FLUID and 51,946 GHO, plus trace cbBTC.

What Actually Left the Protocol, and What Did Not

Fluid’s lending markets, vaults, and DEX liquidity were never in scope for these keys. The drained contracts were reward distributors only. 0xfluid on X confirmed that core protocol smart contracts remained unaffected and user funds were not at risk from the incident.

The stolen FLUID and GHO were swapped for roughly 103 ether through the MetaMask swap router. About 142.6 ETH ended up in Tornado Cash, routed partly through relay wallets and partly by direct deposit. L2 proceeds from Base and Arbitrum were bridged back to Ethereum before mixing.

A large withdrawal of somewhere between $70 and $110 million from Fluid in the days following was not a second exploit. That was depositors pulling their own funds, a confidence-driven bank run. Unrelated to the theft itself, though not exactly unrelated to the disclosure timing.

The Cleanup, and What Was Not Said

About ten hours after the first theft, on May 28 at 07:05 UTC, the Fluid team removed the compromised proposer and approver roles from ten reward distributors in a single batched transaction. Around 314,000 FLUID and 7,400 USDC of remaining reward balances moved to a safe address.

Public communications from the team described only a pause on reward claiming for updates. No mention of a key compromise. No mention of a loss. The exploit itself surfaced publicly on May 31, four days after it happened, when one lender had already pulled $77 million in USDC beginning May 28.

Pablo Veyrat, co-founder of Merkl, addressed the episode on X. Speaking about his own protocol’s design choices, Veyrat noted on X that Merkl runs three independent dispute bots on fully separate infrastructure, each verifying new Merkle trees before a root becomes effective, with a minimum one-hour delay between a new root being posted and any claims going through against it.

Why a Timelock Changes Everything Here

The entire exploit ran in under 24 seconds from proposal to claim. That speed was only possible because no delay existed between root approval and payout. Admin key exploits have hit DeFi repeatedly this year, and the pattern keeps coming back to the same gap: privileged keys with no friction between access and action.

BlackHart’s assessment flagged operational security as the single weakest scoring area in its pre-hack evaluation of Fluid. The exact failure mode, two keys that could be turned into a payout without an independent custodian or a waiting period, was already what the score was warning about. Operational key compromises are not new to 2026, but the Fluid case adds a specific wrinkle: the two-key design looked like a safeguard until it was held by one person.

The attacker’s wallet, 0x4925120c…1d3dfb, claimed across chains within roughly the same minute. No velocity cap bounded what a single cycle could release. No real-time alerting caught the abnormal activity until hours later.

The post $215K Stolen from Fluid: Attacker Controls Both Keys in Merkle Rewards System appeared first on Live Bitcoin News.

Market Opportunity
Instadapp Logo
Instadapp Price(FLUID)
$1.0431
$1.0431$1.0431
+1.07%
USD
Instadapp (FLUID) Live Price Chart

Get Covered, Share 1M USDT

Get Covered, Share 1M USDTGet Covered, Share 1M USDT

Higher VVIP tiers, higher compensation odds.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Covéa Chooses Shift Technology as Strategic Partner for Fraud and Risk Management

Covéa Chooses Shift Technology as Strategic Partner for Fraud and Risk Management

Covéa has selected Shift Technology as a long-term partner to support a consistent and shared view of risk from policy inception through to claims settlement The
Share
ffnews2026/04/02 07:00
One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

The post One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight appeared on BitcoinEthereumNews.com. Frank Sinatra’s The World We Knew returns to the Jazz Albums and Traditional Jazz Albums charts, showing continued demand for his timeless music. Frank Sinatra performs on his TV special Frank Sinatra: A Man and his Music Bettmann Archive These days on the Billboard charts, Frank Sinatra’s music can always be found on the jazz-specific rankings. While the art he created when he was still working was pop at the time, and later classified as traditional pop, there is no such list for the latter format in America, and so his throwback projects and cuts appear on jazz lists instead. It’s on those charts where Sinatra rebounds this week, and one of his popular projects returns not to one, but two tallies at the same time, helping him increase the total amount of real estate he owns at the moment. Frank Sinatra’s The World We Knew Returns Sinatra’s The World We Knew is a top performer again, if only on the jazz lists. That set rebounds to No. 15 on the Traditional Jazz Albums chart and comes in at No. 20 on the all-encompassing Jazz Albums ranking after not appearing on either roster just last frame. The World We Knew’s All-Time Highs The World We Knew returns close to its all-time peak on both of those rosters. Sinatra’s classic has peaked at No. 11 on the Traditional Jazz Albums chart, just missing out on becoming another top 10 for the crooner. The set climbed all the way to No. 15 on the Jazz Albums tally and has now spent just under two months on the rosters. Frank Sinatra’s Album With Classic Hits Sinatra released The World We Knew in the summer of 1967. The title track, which on the album is actually known as “The World We Knew (Over and…
Share
BitcoinEthereumNews2025/09/18 00:02
Not a loophole: Singapore AI export controls let China tap US AI legally

Not a loophole: Singapore AI export controls let China tap US AI legally

American AI technology is reaching Chinese tech giants through a route that US export controls were never designed to close: Singapore. The city-state sits outside
Share
The Cryptonomist2026/07/10 14:46

Record Ads, Stock Down 7%

Record Ads, Stock Down 7%Record Ads, Stock Down 7%

Jul 29: Meta earnings face the market's question.