According to Foresight News, Fluid's Merkle reward distribution system was exploited, resulting in the theft of approximately 163,706 FLUID and 49,526 GHO. Attackers leveraged a remote code execution vulnerability in an internally ported Livewire library to obtain operational keys and submit fraudulent Merkle roots.
The attack only affected backend automation systems; the core protocol, smart contracts, and user funds remained unaffected. Fluid's team has rotated keys, transferred remaining funds, and isolated affected systems. The team committed to covering all losses in full. Merkle reward claims are expected to resume within ten days, with rewards continuing to accrue normally during the interim.