Fluid reward contract was breached, resulting in a loss of approximately $215,000
According to BlackHart, the DeFi project Fluid's reward distribution mechanism on Ethereum was exploited, resulting in approximately $215,000 in assets being transferred away. Fluid uses a Merkle reward list mechanism initiated by one key and approved by another key. The attacker simultaneously held both operational private keys, submitted a list that only awarded themselves, and then completed the claim with a zero-knowledge proof.The stolen assets came from three reward distributors, including 112,883 FLUID, 47,903 GHO, and a small amount of cbBTC, which were later exchanged for ETH and transferred via Tornado Cash. Fluid's lending market, treasury, DEX, and user deposits were unaffected. The team replaced the compromised keys and transferred the remaining reward funds within approximately 10 hours, but the public statement only mentioned that reward claims were paused for updates, without mentioning details about the private key leak and losses.