{"investigation":{"slug":"flamingo-finance","entity_name":"Flamingo Finance","trust_score":22,"severity_base":null,"score_modifier":0,"confidence":0.72,"status":"published","content_type":"investigation","summary":"Flamingo Finance is a NEO-based decentralized finance protocol launched in September 2020 by the Neo Global Development (NGD) team, with involvement from NEO founder Da Hongfei. The protocol suffered two distinct security incidents within weeks of each other in August-September 2026: a staking-contract reward-calculation exploit on approximately August 31, 2026, in which an attacker minted approximately 2.19 trillion FLM tokens and drained liquidity pools; and a separate flash loan attack on September 16, 2026, targeting legacy Flamincome/VaultYUSDT strategy contracts for approximately $345,900 in profit. No official public statements from the Flamingo Finance team had been published in response to either incident as of available reporting.","sections":[{"content":"Flamingo Finance is a full-stack DeFi protocol built on the NEO N3 blockchain. It was incubated by Neo Global Development (NGD) and launched in September 2020, with NEO founder Da Hongfei and team members Adam Yang and Yuan Gao among those associated with the project. On its first day, the protocol attracted approximately $100 million in total value locked (TVL), rising to approximately $1.6 billion within one week. The protocol comprises five core components: Wrapper (cross-chain asset pegging into n-tokens), Swap (AMM-based decentralized exchange for NEP-5 tokens), Vault (yield farming modeled on Yearn Finance), Perp (derivatives platform), and DAO (governance). The Flamincome sub-protocol, launched alongside the main platform, allows users to stake ERC-20 tokens such as USDT, WBTC, and WETH on the Ethereum network to generate yield. FLM is the protocol's governance token, originally issued with a 150 million token supply and no hard cap.","heading":"Protocol Background","sources":[{"url":"https://cryptobriefing.com/project-spotlight-flamingo-finance-chinas-full-stack-defi-protocol/","name":"Project Spotlight: Flamingo Finance, China's Full Stack DeFi Protocol — Crypto Briefing","type":"news_article","credibility":2},{"url":"https://www.investing.com/analysis/project-spotlight-flamingo-finance-chinas-full-stack-defi-protocol-200540079","name":"Project Spotlight: Flamingo Finance — Investing.com","type":"news_article","credibility":2}],"severity":"low"},{"content":"On approximately August 31, 2026, Flamingo Finance suffered a critical exploit targeting a vulnerability in the interaction between its lending and staking contracts. According to reporting by Neo News Today, the flaw existed in how the lending contract called the staking contract to release LP tokens: reward calculations were performed incorrectly, allowing an attacker to mint approximately 2.19 trillion FLM tokens — more than 3,500 times the pre-exploit circulating supply of roughly 570 million FLM. The attacker then sold the minted FLM across all available FLM liquidity pools on the platform, including FLM/WBTC, FLM/FUSD, and FLM/bNEO pairs, collapsing the FLM price and draining most remaining liquidity. Assets acquired by the attacker included WBTC, FUSD, and bNEO; approximately 11,000 bNEO reportedly remained undrained because further pool imbalancing was technically impossible. Lead developer Atlazor was quoted in Discord as stating: 'Someone found that weakness and exploited it to mint a HUGE amount of FLM by claiming FLM rewards with an incorrect reward calculation.' Team member Mr.Google acknowledged in Discord that 'Right now it feels like the damage may be irreversible.' The Neo Council voted to freeze the attacker's address, preventing further movement of the drained assets. No formal post-mortem or official public statement from Flamingo Finance had been published as of available reporting. The total dollar value of assets drained in this incident has not been independently confirmed in available Tier 1 or Tier 2 sources.","heading":"August 2026 Staking Contract Exploit (FLM Minting)","sources":[{"url":"https://neonewstoday.com/defi/flamingo-finance-exploited-through-staking-contract-vulnerability-trillions-of-flm-minted/","name":"Flamingo Finance exploited through staking contract vulnerability, trillions of FLM minted — Neo News Today","type":"news_article","credibility":2},{"url":"https://www.brinztech.com/breach-alerts/brinztech-alert-flamingo-finance-protocol-suffers-critical-exploit-via-staking-logic-flaw","name":"Flamingo Finance Protocol Suffers Critical Exploit via Staking Logic Flaw — BrinzTech","type":"news_article","credibility":2}],"severity":"critical"},{"content":"On September 16, 2026, Flamingo Finance suffered a second distinct security incident. According to security firm Blockaid, which detected and reported the event, an attacker exploited a price-manipulation vulnerability in legacy Flamincome strategy contracts that should have been deprecated. The attacker borrowed approximately $18 million USDT via Morpho flash loans, then staked Curve USDP LP tokens into a Strategy contract during the same transaction to artificially inflate the share price of the VaultYUSDT vault. The attacker then redeemed the inflated vault shares for aUSDT at the manipulated favorable rate, netting approximately $345,900 in profit before repaying the flash loan. The victim contracts involved were identified by Blockaid as: primary victim contract at address 0x0461eEFF7C856020E574c0c364FE968Ca06BCc0F and abused token contract at 0xb8d6471cA573C92c7096Ab8600347F6a9Fe268a5. The attacker's primary address was identified as 0x83381e7F7232775735169d72D237B858fFc36871. Blockchain records show this address received 0.1 ETH from Tornado Cash approximately two hours before the exploit. Within approximately one hour of the exploit, the address executed a 144.15 ETH transfer and interacted with the cross-chain bridge LI.FI. Flamingo Finance had not responded publicly to the incident as of initial reporting. The vulnerability is reported to have existed in older Flamincome contracts that had not been formally deprecated or their liquidity migrated away from.","heading":"September 16, 2026 Flash Loan Exploit (VaultYUSDT / Flamincome)","sources":[{"url":"https://www.cryptotimes.io/2026/09/16/blockaid-flags-flamingofinance-contract-exploit-345-9k-stolen/","name":"Blockaid Flags FlamingoFinance Contract Exploit, $345.9K Stolen — Crypto Times","type":"news_article","credibility":2},{"url":"https://www.kucoin.com/news/flash/flamingofinance-loses-346-000-in-defi-exploit-using-18m-flash-loan","name":"FlamingoFinance Loses $346,000 in DeFi Exploit Using $18M Flash Loan — KuCoin","type":"news_article","credibility":2},{"url":"https://www.kucoin.com/news/flash/flamingo-finance-hacked-attacker-earns-345-900-in-profits","name":"Flamingo Finance Hacked, Attacker Earns $345,900 in Profits — KuCoin","type":"news_article","credibility":2},{"url":"https://phemex.com/news/article/flamingo-finance-exploited-for-about-345900-via-flash-loan-attack-96863","name":"Flamingo Finance Hit by $345,900 Flash Loan Attack — Phemex News","type":"news_article","credibility":2},{"url":"https://panews.io/articles/01a0aa8f-8473-720a-8bea-3d56f4013ff7","name":"Flamingo Finance Suffers an Attack, Attacker Profits Approximately $345,900 — PANews","type":"news_article","credibility":2}],"severity":"critical"},{"content":"On-chain analysis reported by Blockaid identified the primary attacker address associated with the September 16, 2026 flash loan exploit as 0x83381e7F7232775735169d72D237B858fFc36871. Prior to the attack, this address received 0.1 ETH from Tornado Cash — a privacy protocol commonly used to obscure the origin of funds — approximately two hours before executing the exploit. Following the attack, the address moved 144.15 ETH and interacted with LI.FI, a cross-chain bridge and token-swap aggregator, which may have been used to move or convert the proceeds across chains. The source of the 144.15 ETH — whether directly from exploit proceeds or from other holdings — was not independently confirmed in available reporting. The use of Tornado Cash for initial funding and LI.FI for post-exploit movement are consistent with patterns observed in other DeFi exploit cases, though attribution of intent requires caution given available sourcing.","heading":"Attacker Blockchain Activity and Obfuscation","sources":[{"url":"https://www.cryptotimes.io/2026/09/16/blockaid-flags-flamingofinance-contract-exploit-345-9k-stolen/","name":"Blockaid Flags FlamingoFinance Contract Exploit, $345.9K Stolen — Crypto Times","type":"news_article","credibility":2},{"url":"https://www.kucoin.com/news/flash/flamingofinance-loses-346-000-in-defi-exploit-using-18m-flash-loan","name":"FlamingoFinance Loses $346,000 in DeFi Exploit Using $18M Flash Loan — KuCoin","type":"news_article","credibility":2}],"severity":"high"},{"content":"A notable risk factor in the September 16, 2026 flash loan exploit is that the vulnerable contracts were reported to be older Flamincome strategy contracts that had not been formally deprecated. The Flamincome sub-protocol was part of Flamingo Finance's original 2020 launch architecture, designed to allow yield generation on Ethereum-native assets such as USDT. The VaultYUSDT strategy, which was the target of the share-price inflation, appears to have remained accessible to users and liquidity despite being a legacy system. Industry practice in DeFi generally requires that legacy contracts be formally deprecated, migrated, or access-restricted when they are no longer actively maintained, particularly where they interact with newer liquidity pools or vaults. The failure to deprecate these contracts is reported to have been the primary enabling condition for the exploit, according to Blockaid's characterization of the incident.","heading":"Legacy Contract Risk and Deprecation Failures","sources":[{"url":"https://www.cryptotimes.io/2026/09/16/blockaid-flags-flamingofinance-contract-exploit-345-9k-stolen/","name":"Blockaid Flags FlamingoFinance Contract Exploit, $345.9K Stolen — Crypto Times","type":"news_article","credibility":2},{"url":"https://cryptorank.io/news/feed/815dc-flamingofinance-loses-346000-in-defi-exploit-using-18m","name":"FlamingoFinance Loses $346,000 in DeFi Exploit Using $18M Flash Loan — CryptoRank","type":"news_article","credibility":2}],"severity":"high"},{"content":"No regulatory actions, court filings, or government enforcement proceedings against Flamingo Finance, its parent entity Neo Global Development, or associated individuals have been identified in available sources as of September 2026. The protocol is associated with the NEO ecosystem, which has its primary developer community in China. No sanctions designations or OFAC listings for Flamingo Finance or its principals have been identified.","heading":"Regulatory and Legal Status","sources":[],"severity":"low"},{"content":"Flamingo Finance had not published a formal public statement, post-mortem, or incident response document in response to either the August 2026 staking exploit or the September 16, 2026 flash loan exploit as of available reporting. Team members acknowledged the August 2026 incident informally via Discord, with one developer describing potential damage as 'irreversible.' No equivalent acknowledgment was publicly documented for the September incident. The absence of formal transparency disclosures is a material concern for users assessing the protocol's incident response posture.","heading":"Official Response and Transparency","sources":[{"url":"https://neonewstoday.com/defi/flamingo-finance-exploited-through-staking-contract-vulnerability-trillions-of-flm-minted/","name":"Flamingo Finance exploited through staking contract vulnerability, trillions of FLM minted — Neo News Today","type":"news_article","credibility":2}],"severity":"medium"}],"timeline":[{"date":"2020-09-23","event":"Flamingo Finance officially launches on the NEO blockchain. The protocol includes the Flamincome sub-protocol, Wrapper, Swap, and Vault components. TVL reaches approximately $100 million on day one and $1.6 billion within the first week.","source":"Crypto Briefing","source_url":"https://cryptobriefing.com/project-spotlight-flamingo-finance-chinas-full-stack-defi-protocol/"},{"date":"2026-08-31","event":"Flamingo Finance suffers a critical exploit via a reward-calculation flaw in the interaction between its lending and staking contracts. An attacker mints approximately 2.19 trillion FLM tokens (over 3,500x the then-circulating supply) and drains FLM liquidity pools, acquiring WBTC, FUSD, and bNEO. The Neo Council votes to freeze the attacker's address.","source":"Neo News Today","source_url":"https://neonewstoday.com/defi/flamingo-finance-exploited-through-staking-contract-vulnerability-trillions-of-flm-minted/"},{"date":"2026-09-01","event":"Security firm BrinzTech publishes a breach alert characterizing the staking contract exploit as a critical vulnerability in Flamingo Finance's lending-to-staking contract logic.","source":"BrinzTech","source_url":"https://www.brinztech.com/breach-alerts/brinztech-alert-flamingo-finance-protocol-suffers-critical-exploit-via-staking-logic-flaw"},{"date":"2026-09-16","event":"A second distinct exploit targets Flamingo Finance's legacy Flamincome/VaultYUSDT strategy contracts. The attacker borrows approximately $18 million USDT via Morpho flash loans, inflates VaultYUSDT share prices by staking Curve USDP LP tokens, and redeems aUSDT at a favorable rate, netting approximately $345,900. The attacker's address had received 0.1 ETH from Tornado Cash approximately two hours prior. Security firm Blockaid detects and reports the incident. Post-exploit, the address moves 144.15 ETH via LI.FI.","source":"Crypto Times (Blockaid detection report)","source_url":"https://www.cryptotimes.io/2026/09/16/blockaid-flags-flamingofinance-contract-exploit-345-9k-stolen/"}],"sources_used":[{"url":"https://www.cryptotimes.io/2026/09/16/blockaid-flags-flamingofinance-contract-exploit-345-9k-stolen/","name":"Blockaid Flags FlamingoFinance Contract Exploit, $345.9K Stolen — Crypto Times","type":"news_article","archive_url":"http://web.archive.org/web/20260919005701/https://www.cryptotimes.io/2026/09/16/blockaid-flags-flamingofinance-contract-exploit-345-9k-stolen/","credibility":2,"archive_timestamp":"2026-09-19T00:57:01+00:00"},{"url":"https://www.kucoin.com/news/flash/flamingofinance-loses-346-000-in-defi-exploit-using-18m-flash-loan","name":"FlamingoFinance Loses $346,000 in DeFi Exploit Using $18M Flash Loan — KuCoin","type":"news_article","archive_url":"https://web.archive.org/web/20260922125930/https://www.kucoin.com/news/flash/flamingofinance-loses-346-000-in-defi-exploit-using-18m-flash-loan","credibility":2,"archive_timestamp":"2026-09-22T12:59:30+00:00"},{"url":"https://www.kucoin.com/news/flash/flamingo-finance-hacked-attacker-earns-345-900-in-profits","name":"Flamingo Finance Hacked, Attacker Earns $345,900 in Profits — KuCoin","type":"news_article","archive_url":"https://web.archive.org/web/20260922165719/https://www.kucoin.com/news/flash/flamingo-finance-hacked-attacker-earns-345-900-in-profits","credibility":2,"archive_timestamp":"2026-09-22T16:57:19+00:00"},{"url":"https://phemex.com/news/article/flamingo-finance-exploited-for-about-345900-via-flash-loan-attack-96863","name":"Flamingo Finance Hit by $345,900 Flash Loan Attack — Phemex News","type":"news_article","archive_url":"https://web.archive.org/web/20260922125252/https://phemex.com/news/article/flamingo-finance-exploited-for-about-345900-via-flash-loan-attack-96863","credibility":2,"archive_timestamp":"2026-09-22T12:52:52+00:00"},{"url":"https://panews.io/articles/01a0aa8f-8473-720a-8bea-3d56f4013ff7","name":"Flamingo Finance Suffers an Attack, Attacker Profits Approximately $345,900 — PANews","type":"news_article","archive_url":"https://web.archive.org/web/20260922125338/https://panews.io/articles/01a0aa8f-8473-720a-8bea-3d56f4013ff7","credibility":2,"archive_timestamp":"2026-09-22T12:53:38+00:00"},{"url":"https://neonewstoday.com/defi/flamingo-finance-exploited-through-staking-contract-vulnerability-trillions-of-flm-minted/","name":"Flamingo Finance exploited through staking contract vulnerability, trillions of FLM minted — Neo News Today","type":"news_article","archive_url":"http://web.archive.org/web/20260908025528/https://neonewstoday.com/defi/flamingo-finance-exploited-through-staking-contract-vulnerability-trillions-of-flm-minted/","credibility":2,"archive_timestamp":"2026-09-08T02:55:28+00:00"},{"url":"https://www.brinztech.com/breach-alerts/brinztech-alert-flamingo-finance-protocol-suffers-critical-exploit-via-staking-logic-flaw","name":"Flamingo Finance Protocol Suffers Critical Exploit via Staking Logic Flaw — BrinzTech","type":"news_article","archive_url":"https://web.archive.org/web/20260922125636/https://www.brinztech.com/breach-alerts/brinztech-alert-flamingo-finance-protocol-suffers-critical-exploit-via-staking-logic-flaw","credibility":2,"archive_timestamp":"2026-09-22T12:56:36+00:00"},{"url":"https://cryptorank.io/news/feed/815dc-flamingofinance-loses-346000-in-defi-exploit-using-18m","name":"FlamingoFinance Loses $346,000 in DeFi Exploit Using $18M Flash Loan — CryptoRank","type":"news_article","archive_url":null,"credibility":2,"archive_error":"forbiddenaccess","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cryptobriefing.com/project-spotlight-flamingo-finance-chinas-full-stack-defi-protocol/","name":"Project Spotlight: Flamingo Finance, China's Full Stack DeFi Protocol — Crypto Briefing","type":"news_article","archive_url":"http://web.archive.org/web/20260124120716/https://cryptobriefing.com/project-spotlight-flamingo-finance-chinas-full-stack-defi-protocol/","credibility":2,"archive_timestamp":"2026-01-24T12:07:16+00:00"},{"url":"https://www.investing.com/analysis/project-spotlight-flamingo-finance-chinas-full-stack-defi-protocol-200540079","name":"Project Spotlight: Flamingo Finance — Investing.com","type":"news_article","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-09-22T12:08:19.055445+00:00","updated_at":"2026-09-22T16:59:11.192023+00:00"}}