Minimalist USD loses 70.83 ETH in flash-loan exploit
Security & Exploits ·
An attacker manipulated FUM redemption pricing on the Minimalist USD protocol, draining 70.83 ETH from its pool.
The exploit targeted Minimalist USD's FUM redemption mechanism, which the attacker manipulated using a flash loan to distort pricing before extracting funds. Onchain activity tied to the incident is visible on etherscan.io, where the address associated with the exploit shows the transactions involved in the drain.
Flash-loan attacks of this kind typically work by borrowing a large, uncollateralized sum for a single transaction, using it to skew a protocol's internal price calculations, and then exploiting that temporary distortion to extract more value than was deposited — before repaying the loan in the same transaction. In this case, the manipulation centered on how Minimalist USD calculates FUM redemption values, allowing the attacker to redeem at a distorted rate and pull 70.83 ETH out of the pool.
A related account of the same incident describes the loss in dollar terms, putting the damage at $136K and attributing the mechanism to oracle price manipulation carried out with flash-loaned WETH and repeated defund calls used to drain the ETH pool. The two figures — 70.83 ETH and the $136K estimate — describe the same underlying event from different vantage points, with oracle manipulation and FUM redemption pricing pointing to the same core vulnerability in how the protocol prices its redemptions under stress.
Background on ETH's broader role as gas, staking collateral, and DeFi base asset is tracked on leviathan.news, though the exploit itself is specific to Minimalist USD's own pricing logic rather than any flaw in the underlying ETH network.
Not yet known is whether Minimalist USD has paused the affected contract, whether any funds can be recovered or frozen, and whether the protocol plans to patch the redemption pricing mechanism or compensate affected users. It also remains unclear whether the attacker has moved or laundered the extracted ETH, and whether other pools or protocols sharing similar oracle or redemption designs face comparable exposure.