Key Highlights
- Blockaid’s exploit detection system flagged an attack involving older Flamincome contracts associated with FlamingoFinance.
- The attacker used an approximately $18 million USDT flash loan during the exploit.
- USDP liquidity-provider tokens were staked into a strategy, inflating the VaultYUSDT share price.
Blockaid’s exploit detection system identified an attack on older Flamincome contracts associated with FlamingoFinance, a decentralized finance (DeFi) platform.
According to Blockaid’s public report, published on September 16, 2026, an attacker used a flash loan of approximately $18 million in USDT, inflated the share price of the VaultYUSDT by staking USDP liquidity-provider tokens into a strategy contract, and then redeemed liquid aUSDT. The attacker’s profit stood at roughly $345,900 in USDT at the time of the disclosure.
Blockaid listed several addresses linked to the activity and provided the primary exploit transaction hash.
The Crypto Times contacted FlamingoFinance for comment but had not received a response at the time of publication.
On-chain activity linked to the attack

One address identified in connection with the exploit, 0x83381e7F7232775735169d72D237B858fFc36871, shows limited remaining balances on Etherscan. The address held approximately 0.000005 ETH, valued at about $0.01 at the time of the latest recorded data.
The address was funded with 0.1 ETH from Tornado Cash roughly two hours before the main activity cluster. Transaction records list four recent operations, all occurring within approximately one hour of one another. These include a transfer of 144.15 ETH, a token-swap interaction with LI.FI: LiFi Diamond, an approval for Tether USDT, and a contract-creation transaction.
Additional addresses and the primary exploit transaction were also cited in the Blockaid disclosure. The victim and abused token contracts were identified as 0x0461eEFF7C856020E574c0c364FE968Ca06BCc0F and 0xb8d6471cA573C92c7096Ab8600347F6a9Fe268a5.
Attack sequence described by Blockaid
Blockaid stated that the attacker first obtained a large flash-loan amount in USDT. The funds were used to stake USDP LP tokens into a strategy, which in turn raised the reported share price of VaultYUSDT. The elevated share price allowed the subsequent redemption of liquid aUSDT at a favorable rate, generating the recorded profit of approximately $345,900 USDT.
The contracts involved were described as older Flamincome deployments. No further technical breakdown of the pricing mechanism or the precise accounting step that permitted the inflation was included in the initial public notice.
Recent smart-contract security incidents
The Flamincome report follows several other on-chain incidents disclosed in the preceding days.
On September 15, 2026, an Ethereum smart-contract wallet lost approximately 2,900 rsETH, valued at around $7.8 million. The loss occurred after a custom liquidity-provider module attached to the wallet was routed through an attacker-controlled Uniswap v4 pool. The original exploit transaction entered the public mempool but did not settle to the attacker.
A generalized MEV searcher identified as “Yoink” executed first in the same block, captured the position, and moved the bulk of the tokens to a new address. Kelp DAO, the issuer of rsETH, placed a 24-hour wallet-level pause on the receiving address while stating that its core contracts and rsETH backing remained unaffected.
On September 12, 2026, Chainflip, a cross-chain swap protocol, paused its network after an attacker drained 736,442.17 USDT from its Tron settlement path. The project described the event as its first significant critical security incident and stated that the loss was confined to the Tron USDT route.
All other supported chains and remaining funds were reported unaffected. A pending user swap of 115,654.41 USDT remained in the vault and was described as recoverable after a secure restart. Impacted users were told they would be made whole once operations resumed.
On September 9, 2026, Zentra Finance reported an exploit involving its ctUSD reserve on Citrea Mainnet. The protocol estimated losses at approximately $143,000. Lending markets were paused while the team assessed the system and traced funds. No specific vulnerability or attack method was publicly disclosed at the time of the post-mortem.
These earlier incidents involved different protocols, chains, and loss amounts. The Flamincome case centers on the manipulation of share pricing in older vault contracts and the use of a large flash loan to amplify the effect.
Also Read: Ethereum Deploys Multi-Party Block Construction on Mainnet
