Flamingo Finance, the primary DeFi platform on Neo N3, has been exploited through a vulnerability in its staking contract reward calculation. The attacker minted approximately 2.19 trillion FLM tokens, more than 3,500 times the pre-exploit circulating supply of around 570 million, and used them to drain liquidity from the platform’s trading pools. This is a developing story, and the Flamingo team is actively investigating.
How the exploit worked
According to Flamingo team members in the project’s Discord server, the vulnerability exists in the interaction between Flamingo’s lending and staking contracts. Atlazor, Flamingo’s lead developer, explained that when the lending contract calls the staking contract to release LP tokens, the amount is calculated incorrectly, causing the reward calculation to produce inflated results.
Mr.Google, Flamingo team lead, described a compounding issue in the staking contract that could be triggered when extremely small amounts were withdrawn. The attacker exploited this flaw to claim massively inflated FLM rewards, minting over 2.19 trillion tokens in the process.
Atlazor summarized the mechanism:
“Someone found that weakness and exploited it to mint a HUGE amount of FLM by claiming FLM rewards with an incorrect reward calculation.”
The transaction can be viewed on Dora.
Impact on liquidity pools
The minted FLM was immediately sold across all available FLM liquidity pools on Flamingo, including FLM/WBTC, FLM/FUSD, and FLM/bNEO pairs. According to Mr.Google, the exploiter caused an extreme distortion in the market, driving the FLM price down to the lowest level the current orderbook settings allow.
The attacker used the acquired assets, including WBTC, FUSD, and bNEO, to further liquidate remaining liquidity across the platform. According to atlazor, the FUSD pool was not completely emptied, and approximately 11,000 bNEO remained in pools because it was technically impossible to imbalance them further using the OrderBook contract.
Team response
Mr.Google said he left his best friend’s wedding early after learning of the exploit. In a candid message to the Flamingo Discord community, he acknowledged the severity of the situation: “Right now it feels like the damage may be irreversible.”
No official public statement had been published by Flamingo Finance on its social media channels or website at the time of writing. The Discord messages from Mr.Google and atlazor represent the team’s initial response as the investigation continues.
Council action
The Neo Council has since voted to freeze the attacker’s address on the Neo N3 network, preventing the exploiter from moving the remaining assets held at the address.
Neo News Today will provide updates as more information becomes available.
neonewstoday.com