DeFi project Fluid has experienced an exploit on its Ethereum-based reward distribution mechanism, resulting in the loss of approximately $215,000, according to ChainCatcher. The incident involved the misuse of Fluid's Merkle reward list mechanism, which requires one key to initiate and another to approve transactions. The attacker gained control of both operational private keys, allowing them to submit and approve a reward list that directed funds solely to themselves, subsequently using a false proof to claim the rewards.
The stolen assets included 112,883 FLUID tokens, 47,903 GHO tokens, and a small amount of cbBTC, which were converted to ETH and transferred through Tornado Cash. Fluid's lending market, vault, DEX, and user deposits were not affected by the breach. The team responded by replacing the compromised keys and transferring the remaining reward funds within approximately 10 hours. However, their public statement only mentioned a pause in reward updates, without detailing the private key compromise or the extent of the losses.