🚨 EXPLOIT ALERT: $345.9K Drained from @flamincome

Another day, another share-price manipulation exploit.

Root Cause:
Strategy contract treated a permissionless Convex BaseRewardPool balance as its own assets. Attacker injected depegged USDP/3CRV LP tokens, which got valued using Curve's get_virtual_price() — massively inflating the share price. Then redeemed against real Aave aUSDT liquidity for profit.

Classic unsafe accounting + oracle manipulation combo.

Attacker: 0x83381e7f7232775735169d72d237b858ffc36871
Victim Strategy: 0xb8d6471cA573C92c7096Ab8600347F6a9Fe168a5
Flawed Contract: 0xff20De3F3F4C7E9518035a968B4A3CEE500a2AFB

If your protocol relies on external pool balances or virtual price oracles without sanity checks, you're next.

Stay paranoid. Audit your asset accounting.

📊 SlowMist TI