Skip to content

Coins

Flamingo Finance Exploited via Staking Contract Vulnerability as Trillions of FLM Tokens Are Minted

Flamingo Finance, the leading decentralized finance (DeFi) platform on Neo N3, has been exploited through a vulnerability in its staking contract’s reward calculation system. The...

Flamingo Finance, the leading decentralized finance (DeFi) platform on Neo N3, has been exploited through a vulnerability in its staking contract’s reward calculation system.

The attacker minted approximately 2.19 trillion FLM tokens—more than 3,500 times the pre-exploit circulating supply of roughly 570 million FLM—and used the newly created tokens to drain liquidity from Flamingo’s trading pools. The incident remains under investigation.

How the Flamingo Finance exploit worked

According to Flamingo team members in the project’s Discord server, the vulnerability involved the interaction between Flamingo’s lending and staking contracts. Atlazor, Flamingo’s lead developer, said the lending contract incorrectly calculates the amount of LP tokens released through the staking contract, causing the reward calculation to generate inflated results.

Mr.Google, Flamingo’s team lead, described a compounding issue in the staking contract that could be triggered by withdrawing extremely small amounts. The attacker used the flaw to claim vastly inflated FLM rewards, minting more than 2.19 trillion tokens.

Atlazor summarized the mechanism:

“Someone found that weakness and exploited it to mint a HUGE amount of FLM by claiming FLM rewards with an incorrect reward calculation.”

The transaction can be viewed on Dora.

Exploit drains Flamingo liquidity pools

The attacker immediately sold the minted FLM across all available FLM liquidity pools on Flamingo, including the FLM/WBTC, FLM/FUSD, and FLM/bNEO pairs.

According to Mr.Google, the exploit caused an extreme market imbalance and pushed the FLM price down to the lowest level permitted by the current orderbook settings.

The attacker then used the acquired WBTC, FUSD, and bNEO to liquidate additional liquidity across the platform. According to atlazor, the FUSD pool was not completely emptied. Approximately 11,000 bNEO also remained in the pools because the OrderBook contract could not technically imbalance them any further.

Flamingo team responds to the attack

Mr.Google said he left his best friend’s wedding early after learning about the exploit. In a message to the Flamingo Discord community, he acknowledged the seriousness of the incident:

“Right now it feels like the damage may be irreversible.”

At the time of writing, Flamingo Finance had not published an official public statement on its social media channels or website. The Discord messages from Mr.Google and atlazor represent the team’s initial response as the investigation continues.

Neo Council freezes attacker’s address

The Neo Council has since voted to freeze the attacker’s address on the Neo N3 network, preventing the exploiter from moving the remaining assets held there.

Neo News Today will provide further updates as more information becomes available.

Evan Mercer

Penulis

Evan Mercer covers coins, digital assets and the market stories shaping everyday conversations about money. His work focuses on accessible explanations, useful context and the signals behind sudden moves.