FluidTokens Refunds Lenders After Cardano Oracle Feed Exploit
The attack affected one isolated market that accepted FLDT as collateral. The lending protocol will reopen on October 1 at 16:30 UTC, with a full technical analysis still to follow.
By SongMarketCap
Updated:
FluidTokens has reimbursed lenders affected by an attack on its Cardano lending protocol and blocked the smart contract used to extract funds from isolated liquidity pools. The team attributed the incident to an oracle feed issue rather than a vulnerability in the protocol’s validators. It reported that collateral and other token positions were not moved.
The Attack Was Limited to One Lending Market
According to available on-chain analysis, the attack ran from approximately 20:59 UTC on September 29 until 00:48 UTC on September 30. One wallet executed 57 transactions targeting isolated pools that accepted the project’s token as collateral.
Some of the analyzed transactions used one raw unit of FLDT, equal to 0.000001 token, to open substantially larger loans. The pattern suggests a possible unit mismatch in the oracle data, with the price of a full token applied to its smallest accounting unit.
In that scenario, the smart contracts could correctly enforce their loan-to-value rules while using an incorrect price input. FluidTokens has officially confirmed only that the incident involved an oracle feed issue. The unit mismatch remains a finding from independent analysis until the team publishes its post-mortem.
The final amount removed has not been officially disclosed. Decoded transactions account for at least approximately 67,000 ADA, placing the currently identified outflow in the tens of thousands of units of Cardano’s native asset.
Isolated Pools Contained the Impact
FluidTokens is a noncustodial lending protocol launched on Cardano in 2022. Lenders can create liquidity pools, select accepted collateral and define interest rates, loan duration and liquidation conditions. Borrowers can access pools whose terms match the assets they provide as collateral.
Dynamic pools use oracle data to calculate collateral values and available borrowing capacity. The incident therefore centers the technical investigation on the data supplied to the lending contracts rather than the rules enforced by the validators.
Each FluidTokens pool has separately defined liquidity and collateral conditions. This structure prevented the incorrect price input from spreading across other lending markets.
The team said no collateral or other token positions were touched. Funds held in the paused contracts remained inaccessible to both the FluidTokens team and the attacker.
The incident follows the September 13 exploit of Splash’s StableSwap pool, although the two cases have different reported causes. Splash identified missing checks in a validator, while FluidTokens has attributed its incident to external price data used by the lending system.
FluidTokens Reopens Lending on October 1
FluidTokens will reopen its lending protocol on October 1 at 16:30 UTC. Affected lenders were reimbursed before the restart, and the team said it reverse-engineered the attacker’s smart contract and permanently blocked the transaction pattern used in the attack.
Invariant0, the Cardano security team previously known as Vacuumlabs Auditing, assisted with the response. FluidTokens publicly thanked the auditors and community members who helped trace the transactions and analyze the exploit.
The exact source of the incorrect oracle value, the final amount removed and the additional safeguards introduced before reopening have not yet been published. FluidTokens said those details will be included in its full incident analysis.
When lending resumes, the affected lenders will have been made whole, the exploited market path will have been blocked and the paused positions will return without their collateral having been moved. The remaining disclosure is the technical path that allowed an incorrect oracle value to authorize the loans.