Back to Home

Hack of DeFi Protocol Fluid: Theft of FLUID and GHO Tokens

On May 30, 2026, the DeFi protocol Fluid was attacked via a vulnerability in the Merkle tree reward distribution. The attacker gained control of two private keys, created a fake reward list, and withdrew 163,706 FLUID and 49,526 GHO (~$215k). The protocol core and user funds are unaffected; losses will be covered by the team. The incident revealed operational security issues and undermined trust in the reward infrastructure.

DeFi Protocol Fluid Hacked: What Happened to FLUID and GHO Rewards?
Advertisement 728x90

DeFi Protocol Fluid Hacked Amid Reports of FLUID and GHO Token Theft

The attacker exploited a vulnerability in the Merkle reward distribution system, stealing 163,706 FLUID tokens and 49,526 GHO. The protocol team stated that the core protocol and user funds are unaffected, and all losses will be covered.


Fluid Hack: Why the Merkle Tree Attack Was Worse Than the Stolen $215,000

The Core: What's Really Happening

When the Fluid team claims that "the core protocol is unaffected" and "user funds are safe," it's only half true. Yes, the lending pools, DEX, and vaults remain untouched. But the real issue is different: the attack revealed that the reward distribution system, built on two private keys with two-factor approval, collapsed because BOTH keys ended up under the control of a single attacker. This isn't a smart contract hack—it's an operational security failure at an enterprise level.

The attacker exploited the Merkle list mechanism: one key proposed a list of addresses for rewards, and the second key approved it. In a normal scenario, this protects against a single key compromise. But if both keys leak or are initially stored in the same place, the scheme becomes a sham. The hacker simply created a list where all rewards went to their wallet, approved it, and through an empty proof (a technical detail that bypasses verification) withdrew 112,883 FLUID, 47,903 GHO, and some cbBTC.

Google AdInline article slot

Why does this matter for the market? Because Fluid isn't some marginal protocol. It's one of the most integrated DeFi projects on Ethereum, combining lending, vaults, and DEX into a single liquidity layer. Its total value locked (TVL) at the time of the attack was estimated at around $380 million. If the attack had affected core contracts, the consequences would have been catastrophic. But even without that, the blow to trust in the reward infrastructure could trigger a liquidity outflow from pools that depend on FLUID staking.

Timeline and Context

Below is a timeline of events showing how quickly the attack unfolded and how the team responded. Note the gap between the technical fix and public communication:

Date and Time (UTC) Event Consequence
May 30, 2026, ~14:00 Attacker gains control of two Merkle list management keys Two-factor approval system compromised
May 30, ~14:30 Hacker creates and approves a fake reward list to their address Drain process begins from three reward distributors
May 30, ~15:00 112,883 FLUID, 47,903 GHO, and cbBTC transferred to attacker's address Direct losses ~$215,000
May 30, ~16:00 Stolen assets converted to ETH Tracking becomes harder
May 30, ~17:00 ETH sent through Tornado Cash Funds become untraceable
May 30, ~23:00 (9 hours later) Fluid team discovers the hack, replaces compromised keys, moves remaining reward funds to safety Further drain stopped
May 31, ~10:00 (20 hours later) Fluid publishes first message—only about pausing reward distribution No mention of key leak or actual damage
June 1, ~18:00 (52 hours later) After investigation by BlackHart and ChainCatcher, details about private keys emerge Reputational damage grows due to incomplete transparency

What's left out of this table? The main question: HOW did the attacker get both keys? There are three possibilities, none of which reflect well on the team. First: the keys were stored on the same server or in the same cloud storage—a gross violation of the principle of separation of duties. Second: social engineering—the hacker gained access to accounts of two different employees, which is unlikely for a $215k attack. Third: one of the keys was guessed or compromised through a vulnerability in a wallet or repository. The first scenario is most likely—a classic operational security failure in projects that grew too fast.

Google AdInline article slot

Note the FLUID price dynamics. At the time of data publication from Bybit (June 9, 2026), the token traded at $0.8937, down 37.83% from 30 days ago. Other sources showed a price around $1.06 with a 23% weekly drop. In any case, the trend is downward, and the hack news only added to the pressure. GHO, as Aave's stablecoin, remained near its peg at $0.9991-0.9994, which is expected since the theft of 47,903 GHO is a drop in the ocean ($583 million GHO market cap at that time).

Who Wins and Who Loses

Biggest losers: long-term FLUID holders. Their token lost not only in price but also in utility. If the reward system proved vulnerable, future distributions will either be delayed or revised. This means stakers won't get the expected APY. Many FLUID holders joined the loyalty program precisely for these rewards—now their yield is in question.

Losers #2: retail users who didn't withdraw funds from reward contracts in time. Yes, the team said user funds are unaffected. But reward contracts are also user funds, just not in the primary custodial model. The fact that $215,000 was stolen from three distributors means someone didn't receive them. The team promised to cover losses, but from what funds? From the treasury? From FLUID reserves? Or through new token issuance, diluting existing holders?

Google AdInline article slot

Winners: Fluid's competitors in the DeFi super-app segment. Projects like Aave, Compound, or Morpho Blue can use this incident in marketing: "Our reward system is built on battle-tested smart contracts, not two keys in the cloud." Indirectly, Aave itself wins because GHO is its stablecoin. The fact that GHO was stolen but instantly converted to ETH and sent to Tornado Cash confirms GHO's liquidity and fungibility—for a stablecoin, this is a positive signal, paradoxically.

Unobvious winner: Tornado Cash. Every major hack where funds go through a mixer is free advertising for a service under OFAC sanctions. In 2026, Tornado Cash continues to operate around blocks, and the Fluid incident proves hackers still consider it a reliable laundering tool. This creates additional regulatory pressure on DeFi overall, as lawmakers ask: "Why can tokens stolen in 2026 still be laundered through a mixer?"

What the Media Isn't Saying

First: the problem isn't Fluid; it's Merkle trees. An academic study published in August 2025 already warned about vulnerabilities in Merkle proof-based airdrops, including secondary preimage attacks. Fluid used a less secure implementation: one key proposed the reward list, another approved it, and the proof could be empty. In a proper implementation, the proof must be strictly verifiable, not taken on faith. But the team cut corners for gas efficiency—and paid the price.

Second: the Fluid incident isn't isolated in 2026. A month earlier, in April-May, the Drift protocol on Solana lost about $285 million due to an admin key compromise. That was also an attack on privileged access, not a smart contract bug. The trend is clear: hackers are shifting from finding code bugs to hunting for private keys of admins and operators. Because it's easier, faster, and guarantees results. Fluid is the second warning in a month and a half. The third could be devastating.

Third: the team's response split the community. Fluid published a vague statement about "pausing reward distribution," mentioning neither the key compromise nor the actual damage amount. Information about $215,000 and two stolen keys only emerged thanks to independent investigations by BlackHart and ChainCatcher 52 hours after the attack. During that time, some users may have continued staking FLUID, unaware the reward system was compromised. This is a breach of trust that won't be forgotten soon.

Forecast: Next 30 Days and 90 Days

Next 30 days (to mid-July 2026):

FLUID will continue to correct. Technical analysis shows the token broke support at $0.95 and is testing $0.87. The next support zone is $0.80. If the team doesn't publish a detailed post-mortem explaining the key leak and a plan to tighten operational security, selling pressure will persist. FLUID trading volume increased after the attack (on Bitget, $2.47 million per day), but it's panic volume, not accumulation.

GHO will stay near its peg at $0.998-1.002. Aave, as the issuer, isn't directly affected. However, if it turns out that the Merkle tree vulnerability in Fluid was related to GHO integration (e.g., through bridges or facilitators), Aave might temporarily suspend GHO usage in third-party protocols. No such information yet.

Next 90 days (to mid-September):

Fluid will be forced to audit its entire key management system by top-3 firms (Trail of Bits, Sigma Prime, Halborn). Without this, institutional users won't return. The cost of such an audit is $300,000-500,000, which is significant but not fatal for a project with a market cap of $83-88 million. The question is whether the DAO will allocate these funds or the team will try to save money.

In the DeFi market overall, demand for insurance protocols like Nexus Mutual and InsurAce will increase. After the Drift hack and now Fluid, institutions will start demanding insurance for any reward contracts. This could become a growth driver for the DeFi insurance sector, which is currently undervalued. I expect an inflow of $50-100 million into insurance pools within 3 months.

Long-term FLUID holders who don't exit in the coming weeks may receive compensation through new token issuance. This will dilute existing holders by 2-5%, adding further price pressure. Unlocking of these tokens is expected in 6-12 months—prepare for another wave of selling.

Editorial Forecast

Asset: FLUID (Fluid). Direction: Down. Expected range 24-72 hours (by June 17): $0.78–0.85. Confidence level: High (75%), as the news is already partially priced in, but the lack of a transparent post-mortem continues to weigh on price. Technical level $0.87 broken, next stop $0.80. Main risk to forecast: if the Fluid team unexpectedly publishes a detailed report acknowledging mistakes and a concrete compensation plan, the market might see it as a "bottom" and start a bounce to $0.92-0.95. But even then, an upward trend in the next 3 days is unlikely—the memory of the team's secrecy is too fresh. This forecast is an editorial opinion, not investment advice.

— Editorial Team

Advertisement 728x90

Read Next

Partner News