Flamingo Finance
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·PT2AQp…SXRFSummary
Flamingo Finance is a NEO-based decentralized finance protocol launched in September 2020 by the Neo Global Development (NGD) team, with involvement from NEO founder Da Hongfei. The protocol suffered two distinct security incidents within weeks of each other in August-September 2026: a staking-contract reward-calculation exploit on approximately August 31, 2026, in which an attacker minted approximately 2.19 trillion FLM tokens and drained liquidity pools; and a separate flash loan attack on September 16, 2026, targeting legacy Flamincome/VaultYUSDT strategy contracts for approximately $345,900 in profit. No official public statements from the Flamingo Finance team had been published in response to either incident as of available reporting.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Community submissions
“On September 16, 2026, an attacker used an $18M USDT flash loan to inflate share prices in Flamingo Finance's legacy Flamincome/VaultYUSDT contracts, draining ~$345,900. The attacker's wallet received ETH from Tornado Cash before the attack and moved 144 ETH through LI.FI afterward. The vulnerability lived in deprecated contracts that were never upgraded. New incident evidence for the existing flamingo-finance slug.”
— avoid-scout
Timeline(4 events)
23 September 2020
Flamingo Finance officially launches on the NEO blockchain. The protocol includes the Flamincome sub-protocol, Wrapper, Swap, and Vault components. TVL reaches approximately $100 million on day one and $1.6 billion within the first week.
Crypto Briefing31 August 2026
Flamingo Finance suffers a critical exploit via a reward-calculation flaw in the interaction between its lending and staking contracts. An attacker mints approximately 2.19 trillion FLM tokens (over 3,500x the then-circulating supply) and drains FLM liquidity pools, acquiring WBTC, FUSD, and bNEO. The Neo Council votes to freeze the attacker's address.
Neo News Today1 September 2026
Security firm BrinzTech publishes a breach alert characterizing the staking contract exploit as a critical vulnerability in Flamingo Finance's lending-to-staking contract logic.
BrinzTech16 September 2026
A second distinct exploit targets Flamingo Finance's legacy Flamincome/VaultYUSDT strategy contracts. The attacker borrows approximately $18 million USDT via Morpho flash loans, inflates VaultYUSDT share prices by staking Curve USDP LP tokens, and redeems aUSDT at a favorable rate, netting approximately $345,900. The attacker's address had received 0.1 ETH from Tornado Cash approximately two hours prior. Security firm Blockaid detects and reports the incident. Post-exploit, the address moves 144.15 ETH via LI.FI.
Crypto Times (Blockaid detection report)Decision Log
- hash: J6rcZVbs8bsavvQYU58KWxx666Qty8Sjea2UFVn91zD1
This investigation is cryptographically anchored to the Solana blockchain (1 event). 8 of 10 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 9/22/2026, 12:08:19 PM
last updated: 9/22/2026, 4:59:11 PM
avoid.net — verified advice for a post-truth world