{"investigation":{"slug":"flamingo-finance-neo-defi","entity_name":"Flamingo Finance (NEO DeFi)","trust_score":24,"severity_base":null,"score_modifier":0,"confidence":0.68,"status":"draft","content_type":"investigation","summary":"Flamingo Finance is the primary DeFi platform on the Neo N3 blockchain, offering swaps, lending, staking, and cross-chain bridging. In 2026 it suffered at least two distinct exploits within roughly six weeks of each other: an August 31, 2026 staking/lending contract flaw that allowed an attacker to mint approximately 2.1-2.19 trillion FLM tokens and dump them across liquidity pools, and a September 16, 2026 flash-loan attack on legacy Flamincome/VaultYUSDT strategy contracts that yielded the attacker roughly $345,900. The protocol also has a history of cross-chain bridge losses tied to the 2021 Poly Network hack and a subsequent 2024 Poly Network-related exploit, plus a public 2026 governance dispute with Neo Global Development and the Neo Foundation over control of its smart contracts and unfulfilled financial support commitments.","sections":[{"content":"On September 16, 2026, security firm Blockaid flagged an exploit against Flamingo Finance's legacy Flamincome/VaultYUSDT strategy contracts. According to Blockaid and multiple crypto news outlets, an attacker obtained an approximately $18 million USDT flash loan via Morpho, then staked Curve USDP LP tokens into a strategy contract to artificially inflate the share price of VaultYUSDT. The attacker then redeemed liquid aUSDT at the inflated, favorable rate, netting an estimated profit of approximately $345,900. The vulnerability reportedly existed in older contracts associated with the platform's Flamincome yield product that had not been deprecated. Blockaid identified an exploit wallet that had received 0.1 ETH from Tornado Cash approximately two hours before the attack, and which later moved 144.15 ETH and interacted with the LI.FI cross-chain routing protocol, a pattern consistent with attempts to launder or obscure the proceeds. Crypto Times reported that it contacted Flamingo Finance for comment but received no response by publication time; no other outlet reviewed identified a formal public post-mortem for this specific incident as of the time of this investigation. Relative to other DeFi incidents that week, at least one security roundup characterized the loss as a comparatively minor 'on-chain hit' next to larger hacks, but the incident is notable because it stemmed from contracts the protocol itself acknowledged were legacy and should have been retired.","heading":"September 16, 2026 Flash Loan Exploit (VaultYUSDT / Flamincome)","sources":[{"url":"https://www.cryptotimes.io/2026/09/16/blockaid-flags-flamingofinance-contract-exploit-345-9k-stolen/","name":"Blockaid Flags FlamingoFinance Contract Exploit, $345.9K Stolen — Crypto Times","type":"news_article","credibility":2},{"url":"https://www.kucoin.com/news/flash/flamingofinance-loses-346-000-in-defi-exploit-using-18m-flash-loan","name":"FlamingoFinance Loses $346,000 in DeFi Exploit Using $18M Flash Loan — KuCoin","type":"news_article","credibility":2},{"url":"https://www.kucoin.com/news/flash/flamingo-finance-hacked-attacker-earns-345-900-in-profits","name":"Flamingo Finance Hacked, Attacker Earns $345,900 in Profits — KuCoin","type":"news_article","credibility":2},{"url":"https://www.cryptotimes.io/2026/09/21/crypto-hacks-drain-20m-this-week-rseth-safe-nostra-fall/","name":"Crypto Hacks Drain $20M This Week: rsETH, Safe, Nostra Fall — Crypto Times","type":"news_article","credibility":2}],"severity":"high"},{"content":"Roughly two weeks before the flash-loan incident, Flamingo Finance suffered a separate and more severe exploit. According to Neo News Today, an attacker exploited a flaw in how Flamingo's lending contract interacted with its staking contract: the lending contract miscalculated the amount of LP tokens released to the staking contract, which in turn produced grossly inflated reward calculations, particularly when triggered by extremely small withdrawals. Exploiting this, the attacker minted approximately 2.1 to 2.19 trillion FLM tokens — more than 3,500 times the pre-exploit circulating supply of roughly 570 million FLM — and systematically sold them across the platform's FLM/WBTC, FLM/FUSD, and FLM/bNEO liquidity pools, collapsing the FLM price and draining most of the protocol's remaining wrapped-asset liquidity (fWBTC, FUSD, and bNEO), with roughly 11,000 bNEO reportedly unable to be drained due to technical limitations. Flamingo lead developer 'atlazor' stated the attacker 'found that weakness and exploited it to mint a HUGE amount of FLM by claiming FLM rewards with an incorrect reward calculation,' while team lead 'Mr.Google' wrote in Discord that 'right now it feels like the damage may be irreversible.' The Neo Council, which governs the Neo N3 network, subsequently voted to freeze the attacker's address to prevent further movement of remaining funds. As of the sources reviewed, a full post-mortem was still underway and no final loss figure or recovery outcome had been confirmed.","heading":"August 31, 2026 Staking Contract Exploit — Trillions of FLM Minted","sources":[{"url":"https://neonewstoday.com/defi/flamingo-finance-exploited-through-staking-contract-vulnerability-trillions-of-flm-minted/","name":"Flamingo Finance exploited through staking contract vulnerability, trillions of FLM minted — Neo News Today","type":"news_article","credibility":2},{"url":"https://neonewstoday.com/week-in-review/neo-news-week-in-review-august-24-august-30/","name":"Neo News: Week in Review – August 24 – August 30 — Neo News Today","type":"news_article","credibility":2},{"url":"https://www.brinztech.com/breach-alerts/brinztech-alert-flamingo-finance-protocol-suffers-critical-exploit-via-staking-logic-flaw","name":"Flamingo Finance Protocol Suffers Critical Exploit via Staking Logic Flaw — Brinztech","type":"news_article","credibility":2}],"severity":"critical"},{"content":"The September and August 2026 incidents are not isolated. Flamingo Finance's cross-chain bridge, which relies on the Poly Network protocol, was affected by the August 2021 Poly Network exploit (in which approximately $611 million in assets were drained across multiple chains) and was reportedly hit again by a further Poly Network-related exploit that Neo News Today and other outlets describe as a 'third Poly Network hack,' resulting in the loss of an estimated $4-5 million in cross-chain assets (fUSDT, fWBTC, fWETH, fBNB, fCAKE, pWING, pONT) and a multi-month suspension of bridge functionality. In response, Flamingo Finance launched an 'Asset Support Initiative,' compensating affected users with FLOCKS tokens (redeemable 1:1 for FLM) worth an estimated $2.5 million, distributed over two years, with a commitment to halt payments and redistribute recovered funds if the stolen assets were ever recovered. This recurring exposure to bridge and contract-level exploits — three to four distinct loss events across 2021-2026 — indicates a persistent pattern of security and architectural risk rather than a single isolated incident.","heading":"Pattern of Recurring Exploits and Bridge Incidents","sources":[{"url":"https://neonewstoday.com/defi/flamingo-finance-announces-asset-support-initiative-in-wake-of-third-poly-network-hack/","name":"Flamingo Finance announces Asset Support Initiative in wake of third Poly Network hack — Neo News Today","type":"news_article","credibility":2},{"url":"https://www.bitget.com/news/detail/12560604166311","name":"Flamingo Finance Shares Post-Mortem for $5M Poly Network Exploit and Recovery Efforts — Bitget News","type":"news_article","credibility":2},{"url":"https://en.wikipedia.org/wiki/Poly_Network_exploit","name":"Poly Network exploit — Wikipedia","type":"news_article","credibility":2}],"severity":"high"},{"content":"In an open letter reported by Neo News Today on April 22, 2026, Flamingo Finance alleged that Neo Global Development (NGD) and the Neo Foundation (NF) failed to deliver promised financial and operational support while retaining structural control over Flamingo's smart contracts — specifically, upgrade authority — despite having handed day-to-day operational responsibility to a team called MyMingo in 2021. The letter alleged approximately 220,000 USDT plus roughly 20 BTC in undisbursed payments tied to prior bridge-hack fallout, Neo Legacy asset migration, and Poly Network compensation proceeds, and stated that 'expected support became inconsistent. Breaking changes were introduced. Execution slowed or stopped.' The letter also described recurring weekly liquidity shortfalls in bridge operations that left users holding unredeemable wrapped assets. This dispute is relevant to assessing Flamingo Finance's trustworthiness because it indicates the protocol, despite marketing itself as decentralized, does not have full control over its own contract upgrade path — a structural dependency that may bear on accountability for the security incidents described above.","heading":"Governance Dispute with Neo Global Development and Neo Foundation","sources":[{"url":"https://neonewstoday.com/defi/flamingo-finance-airs-support-dispute-with-ngd-and-nf-in-open-letter/","name":"Flamingo Finance airs support dispute with NGD and NF in open letter — Neo News Today","type":"news_article","credibility":2}],"severity":"medium"}],"timeline":[{"date":"2021-08","event":"Poly Network cross-chain protocol suffers a roughly $611 million exploit, affecting bridged assets connected to Flamingo Finance's cross-chain infrastructure on Neo.","source":"Wikipedia / Neo News Today","source_url":"https://en.wikipedia.org/wiki/Poly_Network_exploit"},{"date":"2024-08-12","event":"A further exploit of the Poly Network CMCC cross-chain bridge contract results in the theft of an estimated $4-5 million in assets bridged via Flamingo Finance, prompting a multi-month suspension of cross-chain features.","source":"Bitget News / Neo News Today","source_url":"https://www.bitget.com/news/detail/12560604166311","date_evidence":"The exploit of the Poly Network cross-chain CMCC bridge contract occurred on August 12, 2024, resulting in the theft of approximately $5 million in assets"},{"date":"2026-04","event":"Flamingo Finance publishes an open letter alleging Neo Global Development and the Neo Foundation withheld promised financial support while retaining upgrade control over Flamingo's smart contracts.","source":"Neo News Today","source_url":"https://neonewstoday.com/defi/flamingo-finance-airs-support-dispute-with-ngd-and-nf-in-open-letter/","date_original":"2026-04-22"},{"date":"2026-08","event":"A flaw in Flamingo Finance's staking/lending contract interaction is exploited, allowing an attacker to mint approximately 2.1-2.19 trillion FLM tokens (over 3,500x circulating supply) and drain liquidity pools; the Neo Council freezes the attacker's address.","source":"Neo News Today","source_url":"https://neonewstoday.com/defi/flamingo-finance-exploited-through-staking-contract-vulnerability-trillions-of-flm-minted/","date_original":"2026-08-31"},{"date":"2026-09","event":"Attacker uses an $18 million USDT flash loan to manipulate VaultYUSDT share price via legacy Flamincome strategy contracts, netting approximately $345,900; exploit flagged by Blockaid.","source":"Crypto Times","source_url":"https://www.cryptotimes.io/2026/09/16/blockaid-flags-flamingofinance-contract-exploit-345-9k-stolen/","date_evidence":"Attacker flashloaned ~$18M USDT, inflated VaultYUSDT share price by staking USDP LP into Strategy, then redeemed liquid aUSDT.","date_original":"2026-09-16"}],"sources_used":[{"url":"https://www.cryptotimes.io/2026/09/16/blockaid-flags-flamingofinance-contract-exploit-345-9k-stolen/","name":"Blockaid Flags FlamingoFinance Contract Exploit, $345.9K Stolen — Crypto Times","type":"news_article","archive_url":"http://web.archive.org/web/20260919005701/https://www.cryptotimes.io/2026/09/16/blockaid-flags-flamingofinance-contract-exploit-345-9k-stolen/","credibility":2,"archive_timestamp":"2026-09-19T00:57:01+00:00"},{"url":"https://www.kucoin.com/news/flash/flamingofinance-loses-346-000-in-defi-exploit-using-18m-flash-loan","name":"FlamingoFinance Loses $346,000 in DeFi Exploit Using $18M Flash Loan — KuCoin","type":"news_article","archive_url":"https://web.archive.org/web/20260922125930/https://www.kucoin.com/news/flash/flamingofinance-loses-346-000-in-defi-exploit-using-18m-flash-loan","credibility":2,"archive_timestamp":"2026-09-22T12:59:30+00:00"},{"url":"https://www.kucoin.com/news/flash/flamingo-finance-hacked-attacker-earns-345-900-in-profits","name":"Flamingo Finance Hacked, Attacker Earns $345,900 in Profits — KuCoin","type":"news_article","archive_url":"https://web.archive.org/web/20260922165719/https://www.kucoin.com/news/flash/flamingo-finance-hacked-attacker-earns-345-900-in-profits","credibility":2,"archive_timestamp":"2026-09-22T16:57:19+00:00"},{"url":"https://www.cryptotimes.io/2026/09/21/crypto-hacks-drain-20m-this-week-rseth-safe-nostra-fall/","name":"Crypto Hacks Drain $20M This Week: rsETH, Safe, Nostra Fall — Crypto Times","type":"news_article","archive_url":"http://web.archive.org/web/20260921122949/https://www.cryptotimes.io/2026/09/21/crypto-hacks-drain-20m-this-week-rseth-safe-nostra-fall/","credibility":2,"archive_timestamp":"2026-09-21T12:29:49+00:00"},{"url":"https://neonewstoday.com/defi/flamingo-finance-exploited-through-staking-contract-vulnerability-trillions-of-flm-minted/","name":"Flamingo Finance exploited through staking contract vulnerability, trillions of FLM minted — Neo News Today","type":"news_article","archive_url":"http://web.archive.org/web/20260908025528/https://neonewstoday.com/defi/flamingo-finance-exploited-through-staking-contract-vulnerability-trillions-of-flm-minted/","credibility":2,"archive_timestamp":"2026-09-08T02:55:28+00:00"},{"url":"https://neonewstoday.com/week-in-review/neo-news-week-in-review-august-24-august-30/","name":"Neo News: Week in Review – August 24 – August 30 — Neo News Today","type":"news_article","archive_url":"https://web.archive.org/web/20260922135928/https://neonewstoday.com/week-in-review/neo-news-week-in-review-august-24-august-30/","credibility":2,"archive_timestamp":"2026-09-22T13:59:28+00:00"},{"url":"https://www.brinztech.com/breach-alerts/brinztech-alert-flamingo-finance-protocol-suffers-critical-exploit-via-staking-logic-flaw","name":"Flamingo Finance Protocol Suffers Critical Exploit via Staking Logic Flaw — Brinztech","type":"news_article","archive_url":"https://web.archive.org/web/20260922125636/https://www.brinztech.com/breach-alerts/brinztech-alert-flamingo-finance-protocol-suffers-critical-exploit-via-staking-logic-flaw","credibility":2,"archive_timestamp":"2026-09-22T12:56:36+00:00"},{"url":"https://neonewstoday.com/defi/flamingo-finance-announces-asset-support-initiative-in-wake-of-third-poly-network-hack/","name":"Flamingo Finance announces Asset Support Initiative in wake of third Poly Network hack — Neo News Today","type":"news_article","archive_url":"http://web.archive.org/web/20260916013936/https://neonewstoday.com/defi/flamingo-finance-announces-asset-support-initiative-in-wake-of-third-poly-network-hack/","credibility":2,"archive_timestamp":"2026-09-16T01:39:36+00:00"},{"url":"https://www.bitget.com/news/detail/12560604166311","name":"Flamingo Finance Shares Post-Mortem for $5M Poly Network Exploit and Recovery Efforts — Bitget News","type":"news_article","archive_url":"http://web.archive.org/web/20260916014018/https://www.bitget.com/news/detail/12560604166311","credibility":2,"archive_timestamp":"2026-09-16T01:40:18+00:00"},{"url":"https://en.wikipedia.org/wiki/Poly_Network_exploit","name":"Poly Network exploit — Wikipedia","type":"news_article","archive_url":"http://web.archive.org/web/20260921094137/https://en.wikipedia.org/wiki/Poly_Network_Exploit","credibility":2,"archive_timestamp":"2026-09-21T09:41:37+00:00"},{"url":"https://neonewstoday.com/defi/flamingo-finance-airs-support-dispute-with-ngd-and-nf-in-open-letter/","name":"Flamingo Finance airs support dispute with NGD and NF in open letter — Neo News Today","type":"news_article","archive_url":"http://web.archive.org/web/20260508141627/https://neonewstoday.com/defi/flamingo-finance-airs-support-dispute-with-ngd-and-nf-in-open-letter/","credibility":2,"archive_timestamp":"2026-05-08T14:16:27+00:00"}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-code-investigator","created_at":"2026-09-22T12:05:09.49364+00:00","updated_at":"2026-09-22T16:59:05.056997+00:00"}}