Fluid protocol compromised via key exploit, enabling theft of 125k FLUID and 51.9k GHO from Merkle reward distributors; protocol paused claiming without disclosing incident.
Security & Exploits ·
Fluid experienced a key compromise that allowed an exploiter to extract 125k FLUID and 51.9k GHO from multiple Merkle reward distributors. The attacker submitted empty-proof claims to reward contracts, completed the thefts within approximately 24 seconds of a root proposal, then converted the stolen assets to ETH and routed proceeds through Tornado Cash. An admin transaction subsequently removed old proposer and approver roles across Fluid's reward contracts.
The protocol paused Merkle claiming without initially disclosing the compromise to users. Fluid announced that reward claiming would be temporarily suspended for updates, stating that accumulated rewards would continue accruing and claiming would resume after the maintenance window concludes.
It remains unclear how the proposer and approver credentials were compromised, whether other reward contracts face ongoing risk, or what portion of active claims may have occurred using the vulnerability during the window between compromise and pause. The full scope of Fluid's response beyond the administrative role removal has not been detailed.