T
iTokenly

Flamincome (VaultYUSDT share price) hack — September 2026

Verified — 2 sourcesLast checked September 19, 2026

Incident facts

Date of incident
Target typeStablecoin or yield protocol
Loss$345,900Price at time of incident
MethodContract logic errorOlder Flamincome vault contracts counted an injected balance as their own, so staking USDP liquidity-provider tokens into a strategy contract inflated the VaultYUSDT share price and let the attacker redeem aUSDT at a rate the shares were not worth
ChainsEthereum
OutcomeUnresolved

What happened

An attacker took about $345,900 from old Flamincome vault contracts on Ethereum on 16 September 2026, using a flash loan of roughly $18m in USDT. Flamincome is a yield protocol associated with Flamingo Finance, and the exploited contracts are older deployments that still held funds.

Blockaid, which flagged the exploit, says the attacker inflated the share price of VaultYUSDT by staking USDP liquidity-provider tokens into a strategy contract, then redeemed liquid aUSDT at the inflated rate. SlowMist describes the same failure as flawed asset accounting: the contract treated an injected balance as its own, which overstated what a share was worth. The attacker's wallet had been funded with 0.1 ETH from Tornado Cash beforehand, and afterwards moved 144.15 ETH and interacted with LI.FI.

Flamingo Finance did not respond to The Crypto Times and has published no statement of its own. Nothing has been reported as frozen or recovered.

Sources

  1. The Crypto TimesSecondary · retrieved 2026-09-19
  2. CoinfomaniaSecondary · retrieved 2026-09-19

Changes to this entry

  • Recorded three days after the incident. The amount is the $345,900 that both Blockaid and SlowMist put on the attacker's profit; the DefiLlama dataset lists $595,000 for the same incident, which is not followed here.

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Flamincome (VaultYUSDT share price) hack — September 2026", iTokenly, accessed 2026-09-20, https://itokenly.com/hacks/flamincome-vaultyusdt
https://itokenly.com/hacks/flamincome-vaultyusdt

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.