Flamincome.finance exploited for $346K via oracle manipulation on Curve metapool virtual price and Convex staking deposits.
Security & Exploits ·
Flamincome.finance's USDT strategy contract lost approximately $346,000 in a September 16 exploit targeting oracle pricing logic. The attacker manipulated the virtual price of Curve's USDP metapool by using a Morpho flash loan to purchase USDT cheaply, then imbalance-minted a large quantity of LP tokens and deposited them into Convex while staking on behalf of the strategy contract. This inflated the per-share valuation of the strategy's holdings by exploiting how the contract calculated position value from BaseRewardPool balances multiplied by the metapool's reported virtual price.
When users redeemed YUSDT tokens via the VaultYUSDT contract, the strategy was forced to withdraw approximately 544,000 aUSDT from Aave and pay redemptions at the artificially inflated share price. The strategy incurred total losses of roughly $595,000 in combined aUSDT and USDT, while the attacker captured the difference. The vulnerability stemmed from relying on manipulable on-chain pricing without additional safeguards against rapid share-price movements during large deposits and redemptions.
The exploit highlights risks in strategies that stake collateral into external protocols while using those same protocols' price feeds for valuation. No details have emerged regarding recovery efforts, protocol response, or whether additional safeguards have since been implemented.